Troubleshoot Single Sign-On (SSO) in ServiceTitan

Prev Next

Overview

This article helps you fix sign-in problems with tenant-level Single Sign-On (SSO). It covers connection setup, user linking, sign-in errors, environments, login policy, and profile switching.

Most SSO problems have one of five causes: the user clicked the Classic button, the Next connection is missing, the user is not linked, the user is managed by Enterprise Hub, or the login policy does not match your rollout stage. Start with the Quick diagnosis table, then go to the matching section.

This guide covers the new generation of self-service tenant-level SSO at go.servicetitan.com, currently in Private Preview. For Enterprise Hub SSO, see Troubleshoot Single Sign-On in Enterprise Hub.

Before you troubleshoot, collect:

  • Tenant ID and environment (Go, Next, or both)

  • The user's ServiceTitan username and Entra Object ID

  • Which option the user clicked: the Classic button or the new-generation link

  • The exact error text, plus the Activity ID and Request ID if shown

  • Whether the tenant uses Enterprise Hub

  • The tenant's login policy

Quick diagnosis

Symptom

Most likely cause

“Something went wrong — Can not login via Azure Active Directory”

User clicked the Classic button instead of the new-generation link

SSO settings page not visible

Missing Manage SSO Configuration permission

Connection stuck on Pending

Microsoft admin consent not completed

User can sign in to Go but not Next

No SSO connection set up in Next

User appears read-only in the SSO user list

User is managed by Enterprise Hub SSO

User never sees the auto-link prompt

First login was in Next, or the Entra identity is linked elsewhere

User asked for a username and password instead of Entra

User not linked, or wrong Object ID entered

Whole tenant locked out after a policy change

SSO Only enabled before all users were linked

Technician cannot switch profiles in the mobile app

The switcher cannot reopen after the first selection

Link User drawer shows a load error

Browser popup blocked, often in Safari full-screen

Connection setup issues


The Single Sign-On settings page is not visible

The role is missing the Manage SSO Configuration permission. Add it to the role, then refresh the page. Linking users needs a second permission, Manage SSO Access.

The connection is stuck on Pending

Pending means the connection exists but Microsoft admin consent is not complete.

  1. Go to Settings > Integrations > Single Sign-On.

  2. Click the clipboard icon to copy the setup URL again.

  3. Open the URL in a new tab. Sign in with a Microsoft Entra administrator account.

  4. Review the permissions and click Accept.

If you are not an Entra administrator, forward the URL to someone who is. The status changes to Active after consent.

Microsoft shows Need admin approval during consent

The account is not an Entra administrator, or your organization blocks user consent for third-party apps. Send the setup URL to an Entra Global Administrator or Application Administrator.

The setup URL was not copied

Some browsers block clipboard access. Find the connection in the list. Click the clipboard icon to copy the URL manually.

Check that the Entra Tenant ID on the connection matches your organization's Entra tenant. If it is wrong, delete the connection and re-enter it.

You see an error adding a second connection for the same Entra tenant

Each connection must point to a different Entra tenant. Use one connection per Entra tenant. You need more than one only if your organization uses multiple Entra tenants, such as one per brand.

Two connections have the same name

Connection names do not need to be unique. Click Edit to rename one so you can tell them apart.

Deactivate compared to Delete

Action

User links

Microsoft consent

Use when

Deactivate

Kept

Kept, no re-consent needed

Troubleshooting or changing settings

Delete

Permanently removed

Must be redone

Removing the integration entirely

User linking issues


A user does not appear in the SSO user list

SSO links only users who already exist in ServiceTitan and have accepted their invitation. Create the user first. Have them set up their account, then link them. Automatic user provisioning is not available, so create users manually.

A user appears read-only

The user is managed by Enterprise Hub SSO, or an employee and technician account are linked together. A user cannot use Enterprise Hub SSO and tenant-level SSO at the same time. Manage that user in Enterprise Hub > User Management > Security. If the user should be editable, check with your Enterprise Hub administrator.

The Link User drawer shows Sorry, can't load the data. The Microsoft sign-in popup was blocked or did not close. This is most common in Safari full-screen mode.

  1. Exit full-screen mode, or switch to Chrome or Edge.

  2. Allow popups for servicetitan.com.

  3. Refresh the page and try again.

  4. If it still fails, enter the user's Object ID manually.

Linking fails with an invalid Object ID

The value entered is not the user's Entra Object ID. The Object ID is a GUID. Find it in the Microsoft Entra admin center under Users > [the user] > Overview. Do not use the email, UPN, or Entra Tenant ID.

Check these in order:

  1. Auto-link is on for the connection. It is off by default.

  2. The user signs in at go.servicetitan.com. Auto-link is not available in Next.

  3. The user clicked the new-generation link, not the Classic button.

  4. The user's Entra identity is not already linked. Auto-link works once per Entra identity across all tenants. If it was used before, an admin must link other profiles manually.

A user was auto-linked to the wrong profile

Unlink the user from Connection Details. Then link the correct profile manually with the Object ID. Auto-link works only once, so the user cannot redo it.

Unlinking deletes the stored Entra data for that profile. Re-link the user manually with the Object ID. To pause SSO instead, use Disable, which keeps the link.

A user was unlinked but is still signed in

Removing a link does not end the current session. The change takes effect at the next sign-in. To stop access now, deactivate the user.

Sign-in errors


“Something went wrong — Can not login via Azure Active Directory”

The user clicked the Sign in with Microsoft Entra — Classic button, but the account is not set up for Classic SSO. This screen also appears when the tenant has no SSO configured. Retrying the same button always fails.

  1. Click Back to sign in.

  2. Click the Using the new generation of SSO? Sign in with Microsoft Entra link below the Classic button.

  3. If it still fails, contact ServiceTitan Support with the Activity ID and Request ID.

The user is asked for a username and password instead of Entra

The user is not linked, or the Object ID is wrong. Check the SSO user list:

  • Not Linked: link the user, or have them complete auto-link.

  • Disabled: re-enable SSO from Connection Details.

  • Enabled: compare the Object ID on the link with the one in Entra. If they differ, unlink and re-link.

A linked user is asked for a password

Return to the login screen. Use the new-generation Sign in with Microsoft Entra link.

Sign-in failed or SSO Required

The tenant is on SSO Only and the user tried a password. Have them use the new-generation Entra link. If the user is not linked, see Users are locked out after the tenant moved to SSO Only below.

The user signs in with the wrong Microsoft account

The browser reused a cached Microsoft session. Have the user sign out at microsoft.com, or use a private window. Then pick the account for the organization configured for SSO.

Microsoft MFA prompts appear or do not appear

ServiceTitan does not control MFA for SSO users; your Entra administrators do. If the user's Entra MFA session is still valid, they are not prompted again. Send MFA questions to your IT team.

No Sign Out option after using the profile switcher

Close the browser, or clear cookies for servicetitan.com, to end the session.

Go and Next environment issues

Go and Next need separate SSO connections. User links are created in Go and carry over to Next.

Task

Go

Next

Create an SSO connection

Yes

Yes, separately, with its own admin consent

Link users manually

Yes

No, the linking screen is not available

Auto-link

Yes

No

User links

Created here

Copied automatically from Go


A user can sign in to Go but not Next

The Next environment has no Active SSO connection. Create the connection in Next and complete Microsoft admin consent. The Go link applies once the connection is active.

You cannot find the user linking screen in Next

This is expected. Link users in Go. The links carry over to Next automatically.

A new user's first sign-in was in Next and nothing happened

Auto-link runs only in Go. Send the user to go.servicetitan.com to auto-link, or link them manually in Go. Next then works with SSO.

Confirm the Next connection is Active. Have the user sign out of Next and sign in again. If it still fails, contact ServiceTitan Support with the Object ID and both environment names.

Login policy issues

ServiceTitan sets the login policy, not the tenant administrator. The default is SSO If Linked. To change it, contact your CSM or open a support ticket.

Policy

Linked users

Unlinked users

SSO If Linked (default)

Must use SSO

Use username and password

Mixed

SSO or password

SSO or password

SSO Only

Must use SSO

Locked out, unless auto-link is available


You cannot find where to change the policy

This is expected. The policy is not shown in tenant settings. Contact your CSM or open a support ticket.

Users are locked out after the tenant moved to SSO Only

Some users were not linked before the change. Unlinked users can still auto-link with the new-generation link, unless their Entra identity is linked elsewhere.

  1. Find users with Not Linked status in the SSO user list.

  2. Link each one manually with the Object ID.

  3. If many users are affected, contact ServiceTitan Support to switch the tenant to Mixed until linking is done.

Before you request SSO Only

Confirm all of the following first:

  • Every user shows Enabled in the SSO user list

  • Connections are Active in every environment users need

  • You have a way to link new users whose Entra identity is already in use

  • At least one administrator has signed in with SSO successfully

Multiple profiles and the mobile app

One Entra identity can link to several ServiceTitan profiles. After sign-in, the profile switcher asks which profile to open.


A technician cannot switch profiles in the mobile app

Technicians see the profile picker at first sign-in. After they pick a profile, the switcher cannot reopen in the app. To switch, sign out and sign back in.

The profile switcher looks blank on Android

Verify the user has the latest browser version. Have the technician sign out and back in. If the screen stays blank,  contact ServiceTitan Support with the device model and Android version.

An account does not respond on the first tap

Tap the account again. The second tap registers.

The switcher shows no accounts after switching

Sign out and sign back in to refresh the list.

Classic SSO customers

If you use Classic Azure Active Directory SSO, keep using the Classic button until you migrate. ServiceTitan begins moving Classic customers to the new generation in November 2026. Your CSM contacts you before your migration window.


You are on Classic SSO and want self-service now

Self-service SSO in Private Preview is for tenants not on Classic SSO. Contact your CSM to schedule migration instead of adding a second connection.

A Classic user clicked the new-generation link

The account is not linked in the new system, so sign-in fails or asks for a password. Use the Classic button until your tenant is migrated.

After migration, users still click Classic

They get the Can not login via Azure Active Directory error. Have them use the new-generation Entra link instead.

Want to learn more?