Overview
This article helps you fix sign-in problems with tenant-level Single Sign-On (SSO). It covers connection setup, user linking, sign-in errors, environments, login policy, and profile switching.
Most SSO problems have one of five causes: the user clicked the Classic button, the Next connection is missing, the user is not linked, the user is managed by Enterprise Hub, or the login policy does not match your rollout stage. Start with the Quick diagnosis table, then go to the matching section.
This guide covers the new generation of self-service tenant-level SSO at go.servicetitan.com, currently in Private Preview. For Enterprise Hub SSO, see Troubleshoot Single Sign-On in Enterprise Hub.
Before you troubleshoot, collect:
Tenant ID and environment (Go, Next, or both)
The user's ServiceTitan username and Entra Object ID
Which option the user clicked: the Classic button or the new-generation link
The exact error text, plus the Activity ID and Request ID if shown
Whether the tenant uses Enterprise Hub
The tenant's login policy
Quick diagnosis
Symptom | Most likely cause |
|---|---|
“Something went wrong — Can not login via Azure Active Directory” | User clicked the Classic button instead of the new-generation link |
SSO settings page not visible | Missing Manage SSO Configuration permission |
Connection stuck on Pending | Microsoft admin consent not completed |
User can sign in to Go but not Next | No SSO connection set up in Next |
User appears read-only in the SSO user list | User is managed by Enterprise Hub SSO |
User never sees the auto-link prompt | First login was in Next, or the Entra identity is linked elsewhere |
User asked for a username and password instead of Entra | User not linked, or wrong Object ID entered |
Whole tenant locked out after a policy change | SSO Only enabled before all users were linked |
Technician cannot switch profiles in the mobile app | The switcher cannot reopen after the first selection |
Link User drawer shows a load error | Browser popup blocked, often in Safari full-screen |
Connection setup issues
The Single Sign-On settings page is not visible
The role is missing the Manage SSO Configuration permission. Add it to the role, then refresh the page. Linking users needs a second permission, Manage SSO Access.
The connection is stuck on Pending
Pending means the connection exists but Microsoft admin consent is not complete.
Go to Settings > Integrations > Single Sign-On.
Click the clipboard icon to copy the setup URL again.
Open the URL in a new tab. Sign in with a Microsoft Entra administrator account.
Review the permissions and click Accept.
If you are not an Entra administrator, forward the URL to someone who is. The status changes to Active after consent.
Microsoft shows Need admin approval during consent
The account is not an Entra administrator, or your organization blocks user consent for third-party apps. Send the setup URL to an Entra Global Administrator or Application Administrator.
The setup URL was not copied
Some browsers block clipboard access. Find the connection in the list. Click the clipboard icon to copy the URL manually.
Consent succeeded but users cannot sign in
Check that the Entra Tenant ID on the connection matches your organization's Entra tenant. If it is wrong, delete the connection and re-enter it.
You see an error adding a second connection for the same Entra tenant
Each connection must point to a different Entra tenant. Use one connection per Entra tenant. You need more than one only if your organization uses multiple Entra tenants, such as one per brand.
Two connections have the same name
Connection names do not need to be unique. Click Edit to rename one so you can tell them apart.
Deactivate compared to Delete
Action | User links | Microsoft consent | Use when |
|---|---|---|---|
Deactivate | Kept | Kept, no re-consent needed | Troubleshooting or changing settings |
Delete | Permanently removed | Must be redone | Removing the integration entirely |
User linking issues
A user does not appear in the SSO user list
SSO links only users who already exist in ServiceTitan and have accepted their invitation. Create the user first. Have them set up their account, then link them. Automatic user provisioning is not available, so create users manually.
A user appears read-only
The user is managed by Enterprise Hub SSO, or an employee and technician account are linked together. A user cannot use Enterprise Hub SSO and tenant-level SSO at the same time. Manage that user in Enterprise Hub > User Management > Security. If the user should be editable, check with your Enterprise Hub administrator.
The Link User drawer shows a load error
The Link User drawer shows Sorry, can't load the data. The Microsoft sign-in popup was blocked or did not close. This is most common in Safari full-screen mode.
Exit full-screen mode, or switch to Chrome or Edge.
Allow popups for servicetitan.com.
Refresh the page and try again.
If it still fails, enter the user's Object ID manually.
Linking fails with an invalid Object ID
The value entered is not the user's Entra Object ID. The Object ID is a GUID. Find it in the Microsoft Entra admin center under Users > [the user] > Overview. Do not use the email, UPN, or Entra Tenant ID.
A user never sees the auto-link prompt
Check these in order:
Auto-link is on for the connection. It is off by default.
The user signs in at go.servicetitan.com. Auto-link is not available in Next.
The user clicked the new-generation link, not the Classic button.
The user's Entra identity is not already linked. Auto-link works once per Entra identity across all tenants. If it was used before, an admin must link other profiles manually.
A user was auto-linked to the wrong profile
Unlink the user from Connection Details. Then link the correct profile manually with the Object ID. Auto-link works only once, so the user cannot redo it.
A user was unlinked and cannot auto-link again
Unlinking deletes the stored Entra data for that profile. Re-link the user manually with the Object ID. To pause SSO instead, use Disable, which keeps the link.
A user was unlinked but is still signed in
Removing a link does not end the current session. The change takes effect at the next sign-in. To stop access now, deactivate the user.
Sign-in errors
“Something went wrong — Can not login via Azure Active Directory”
The user clicked the Sign in with Microsoft Entra — Classic button, but the account is not set up for Classic SSO. This screen also appears when the tenant has no SSO configured. Retrying the same button always fails.
Click Back to sign in.
Click the Using the new generation of SSO? Sign in with Microsoft Entra link below the Classic button.
If it still fails, contact ServiceTitan Support with the Activity ID and Request ID.
The user is asked for a username and password instead of Entra
The user is not linked, or the Object ID is wrong. Check the SSO user list:
Not Linked: link the user, or have them complete auto-link.
Disabled: re-enable SSO from Connection Details.
Enabled: compare the Object ID on the link with the one in Entra. If they differ, unlink and re-link.
A linked user is asked for a password
Return to the login screen. Use the new-generation Sign in with Microsoft Entra link.
Sign-in failed or SSO Required
The tenant is on SSO Only and the user tried a password. Have them use the new-generation Entra link. If the user is not linked, see Users are locked out after the tenant moved to SSO Only below.
The user signs in with the wrong Microsoft account
The browser reused a cached Microsoft session. Have the user sign out at microsoft.com, or use a private window. Then pick the account for the organization configured for SSO.
Microsoft MFA prompts appear or do not appear
ServiceTitan does not control MFA for SSO users; your Entra administrators do. If the user's Entra MFA session is still valid, they are not prompted again. Send MFA questions to your IT team.
No Sign Out option after using the profile switcher
Close the browser, or clear cookies for servicetitan.com, to end the session.
Go and Next environment issues
Go and Next need separate SSO connections. User links are created in Go and carry over to Next.
Task | Go | Next |
|---|---|---|
Create an SSO connection | Yes | Yes, separately, with its own admin consent |
Link users manually | Yes | No, the linking screen is not available |
Auto-link | Yes | No |
User links | Created here | Copied automatically from Go |
A user can sign in to Go but not Next
The Next environment has no Active SSO connection. Create the connection in Next and complete Microsoft admin consent. The Go link applies once the connection is active.
You cannot find the user linking screen in Next
This is expected. Link users in Go. The links carry over to Next automatically.
A new user's first sign-in was in Next and nothing happened
Auto-link runs only in Go. Send the user to go.servicetitan.com to auto-link, or link them manually in Go. Next then works with SSO.
A link made in Go is not working in Next
Confirm the Next connection is Active. Have the user sign out of Next and sign in again. If it still fails, contact ServiceTitan Support with the Object ID and both environment names.
Login policy issues
ServiceTitan sets the login policy, not the tenant administrator. The default is SSO If Linked. To change it, contact your CSM or open a support ticket.
Policy | Linked users | Unlinked users |
|---|---|---|
SSO If Linked (default) | Must use SSO | Use username and password |
Mixed | SSO or password | SSO or password |
SSO Only | Must use SSO | Locked out, unless auto-link is available |
You cannot find where to change the policy
This is expected. The policy is not shown in tenant settings. Contact your CSM or open a support ticket.
Users are locked out after the tenant moved to SSO Only
Some users were not linked before the change. Unlinked users can still auto-link with the new-generation link, unless their Entra identity is linked elsewhere.
Find users with Not Linked status in the SSO user list.
Link each one manually with the Object ID.
If many users are affected, contact ServiceTitan Support to switch the tenant to Mixed until linking is done.
Before you request SSO Only
Confirm all of the following first:
Every user shows Enabled in the SSO user list
Connections are Active in every environment users need
You have a way to link new users whose Entra identity is already in use
At least one administrator has signed in with SSO successfully
Multiple profiles and the mobile app
One Entra identity can link to several ServiceTitan profiles. After sign-in, the profile switcher asks which profile to open.
A technician cannot switch profiles in the mobile app
Technicians see the profile picker at first sign-in. After they pick a profile, the switcher cannot reopen in the app. To switch, sign out and sign back in.
The profile switcher looks blank on Android
Verify the user has the latest browser version. Have the technician sign out and back in. If the screen stays blank, contact ServiceTitan Support with the device model and Android version.
An account does not respond on the first tap
Tap the account again. The second tap registers.
The switcher shows no accounts after switching
Sign out and sign back in to refresh the list.
Classic SSO customers
If you use Classic Azure Active Directory SSO, keep using the Classic button until you migrate. ServiceTitan begins moving Classic customers to the new generation in November 2026. Your CSM contacts you before your migration window.
You are on Classic SSO and want self-service now
Self-service SSO in Private Preview is for tenants not on Classic SSO. Contact your CSM to schedule migration instead of adding a second connection.
A Classic user clicked the new-generation link
The account is not linked in the new system, so sign-in fails or asks for a password. Use the Classic button until your tenant is migrated.
After migration, users still click Classic
They get the Can not login via Azure Active Directory error. Have them use the new-generation Entra link instead.