Skip to content

Troubleshooting

Find the message or symptom you see, then follow the fix. If nothing here matches, see Support for what to send Xertone.

Dashboard keeps loading, or sign-in shows AADSTS7000112

Section titled “Dashboard keeps loading, or sign-in shows AADSTS7000112”

Symptom. The TeamsPIM Dashboard tab spins and never loads. A sign-in window may show “Sorry, but we’re having trouble signing you in” with:

AADSTS7000112: Application '1fec8e78-bce4-4aaf-ab1b-5451cc387264'(Microsoft Teams) is disabled.

Cause. Your tenant has disabled sign-in for the Microsoft Teams enterprise application. TeamsPIM signs users in through Teams, so it cannot get a token.

Fix. An administrator with the Cloud Application Administrator or Application Administrator role re-enables sign-in for the Microsoft Teams enterprise app.

In the Microsoft Entra admin center:

  1. Go to Enterprise apps > All applications.
  2. Remove the “Application type == Enterprise Applications” filter. Microsoft’s own apps are hidden while it is applied.
  3. Search for 1fec8e78-bce4-4aaf-ab1b-5451cc387264 and open Microsoft Teams.
  4. Open Properties, set “Enabled for users to sign-in?” to Yes, and select Save.

Or with Microsoft Graph PowerShell:

Terminal window
Connect-MgGraph -Scopes "Application.ReadWrite.All"
$Sp = Get-MgServicePrincipal -Filter "appId eq '1fec8e78-bce4-4aaf-ab1b-5451cc387264'"
Update-MgServicePrincipal -ServicePrincipalId $Sp.Id -AccountEnabled:$true

Then wait a few minutes, fully quit Teams and start it again.

Teams on the web uses a different application, Microsoft Teams Web Client (5e3ce6c0-2b1f-4285-8d4b-75ee78787346). If the error names that ID, apply the same fix to it: search for that ID in the admin center, or use it in place of 1fec8e78-bce4-4aaf-ab1b-5451cc387264 in the PowerShell above.

Microsoft documents this property in Disable user sign-in for an application and Properties of an enterprise application.

Symptom Cause Fix
“No TeamsPIM license assigned” The user has no TeamsPIM licence. An administrator assigns one on the Licenses page of the Customer Admin Portal. The user then reopens the app. See Assign licences.
“The license check could not be completed. Please try again.” TeamsPIM could not finish checking the licence. Try again. If it keeps happening, contact support.
“We couldn’t sign you in. Check your connection and try again.” Sign-in could not complete, often a network problem. Check the connection and select Try again.
“Set up multi-factor authentication” Your organisation requires MFA and the user has not registered for it. Register at aka.ms/mfasetup, then sign out of Teams and sign back in.
“Additional verification required” The role’s PIM settings require a Conditional Access authentication context. Select Verify and complete the sign-in prompt.
“Sign in to Teams again to continue” Multi-factor authentication needs a fresh sign-in. Sign out of Teams and sign back in.
“Switching directory is not set up” One of the three requirements for Switch Directory is missing. Make sure the subscription is active, the user has a licence, and additional directories are added in Subscription Settings. See Additional directories.
“Open TeamsPIM in Microsoft Teams” The Dashboard was opened in a browser outside Teams. Select Open Microsoft Teams and use the TeamsPIM tab there.
TeamsPIM did not appear in Teams after a licence was assigned A Teams app permission policy blocks TeamsPIM, or it is not in your Teams app catalogue. The automatic install fails silently. Allow TeamsPIM in the Teams admin center, then turn the user’s licence off and on to re-save it. Or the user installs TeamsPIM from the Teams store. See Deploy in Teams.
A just-activated role does not show as active yet Microsoft Entra takes a few seconds to apply the activation. Wait a few seconds and refresh the tab.
“Request creating failed.” followed by another message Microsoft Entra refused the request. The second part is Entra’s own message. Act on Entra’s message, for example the role’s settings or an existing pending request for the same role.
Azure role requests on a subscription are not handled TeamsPIM is not assigned to that Azure subscription. Nothing is assigned automatically. An Owner or User Access Administrator assigns it on the Azure Resources page. See Azure resources.
Symptom Cause Fix
An approver gets no approval cards The approver has no TeamsPIM licence, is not an approver in the role’s PIM settings, or TeamsPIM is not installed for them. Assign a licence, check the approvers in Entra PIM role settings, and make sure the app is installed.
The card shows “To continue please sign in” with Sign In Approvals run as the approver, so TeamsPIM needs them signed in. This also happens when MFA or Conditional Access needs interaction. Select Sign In, complete the sign-in, then select Approve or Deny again.
“Justification text is required.” The justification box was empty. Enter a justification and select the button again.
“PIM Request card is stale. The request may have already been processed.” Another approver already decided, or the request was cancelled or expired. Nothing to do. The card shows the outcome once it updates.
“This request is already being processed. Please wait for the result.” A decision is in progress. Wait for the card to update.
“Action failed. Please try again or contact support.” The approval or denial did not go through. Try again. If it keeps failing, contact support with the time and the card details.
“PIM Request not found.” The request no longer exists in PIM. Nothing to approve. The requestor can submit a new request if still needed.
An approver cannot approve their own request PIM does not allow self-approval. Another approver has to decide.
The request shows “Expired” The approval window ran out. PIM, not TeamsPIM, sets it. The requestor submits a new request.
Symptom Cause Fix
“Subscription not found” on the landing page The landing page was not opened from the Marketplace. Open your TeamsPIM subscription in AppSource or the Azure Marketplace and select Configure account now.
“Signed in with a different account” You are not signed in with the purchasing account. Select Sign out & switch account and sign in as the purchaser.
“Admin consent not verified yet. Complete consent and try again.” Consent was not finished, or was granted in a different tenant. Complete consent in the same tenant as the purchase and try again. See Admin consent.
“Your organisation hasn’t approved TeamsPIM yet.” when signing in to the Customer Admin Portal (AADSTS500011 or AADSTS65001) TeamsPIM has no admin consent in your tenant. A Global Administrator grants consent, or you copy the link and send it to one.
The Overview stays on Waiting for review Xertone has not finished reviewing your request. Wait for the email. If you have questions, contact support.
Setup failed on the Overview Setting up your tenant’s back end failed. Contact support with your tenant ID. See Review and provisioning.
Symptom Cause Fix
“TeamsPIM has not been approved for your organisation yet.” TeamsPIM has no admin consent in your tenant. Select Grant admin consent if you are a Global Administrator, or Copy link and send it to one.
“You do not have access to manage this subscription.” You are neither the purchaser nor an added administrator. Ask the purchaser to add you under Administrators in Subscription Settings.
“User has license assignment.” The person already holds a TeamsPIM licence under another subscription. Unassign it under the other subscription first.
“Subscription limit exceeded.” Every seat is in use. Add seats with Microsoft. See Manage your subscription.
“This tenant is not linked to the subscription.” (TENANT_NOT_LINKED) The tenant is not in the subscription’s additional tenant IDs. Add it in Subscription Settings.
“This subscription’s tenant has not granted TeamsPIM admin consent.” (TENANT_CONSENT_MISSING) That tenant has not consented to TeamsPIM. Grant consent for that tenant, then add it in Subscription Settings.
“Admin consent is missing for this tenant.” when adding a tenant Consent was revoked or not completed. Grant consent again, select Verify, then Add.
“This tenant ID cannot be removed.” It is the subscription’s own tenant. This tenant always stays on the subscription.
Symptom Cause Fix
“This tenant requires multi-factor authentication to access Azure.” (AZURE_MFA_REQUIRED) Your account has not completed MFA in that tenant. Sign in to portal.azure.com, switch to that directory and complete MFA. Then sign out of the Customer Admin Portal, sign back in and pick the tenant again.
“You cannot change access at this scope.” (INSUFFICIENT_AZURE_RBAC) You are not Owner or User Access Administrator on the Azure subscription. Get one of those roles, or ask someone who has it to assign TeamsPIM.
“Assign app failed.” or “Unassign app failed.” Azure refused the change. Read the message under it, fix the cause and try again.
An Azure subscription is missing from the list Your account cannot access it in the selected tenant. Pick the right tenant in “Select a tenant”, or get access to the subscription.