Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Adding a person to your space

Bill A Baker
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
June 10, 2026

I have added a person to the space as a business user, but they got this message: 

Ameriprise 
Atlassian_support_portal_saml_idp_spflow_external
rry, but we're having trouble signing you in.
AADSTS50105: Your administrator has configured the application
Atlassian_support_portal_saml_idp_spflow_external ('eee004b4-cee1-4769-84a6
Of384965594c') to block users unless they are specifically granted ('assigned')
access to the application. The signed in user 'Siva.*********@ampf.com' is
blocked because they are not a direct member of a group with access, nor had
access directly assigned by an administrator. Please contact your administrator to
assign access to this application.

2 answers

1 vote
Hamza Chundrigar
June 10, 2026

Hi @Bill A Baker 

That error is coming from Microsoft Entra ID, not from Jira, so nothing you grant inside Atlassian will clear it.

AADSTS50105 means Entra didn’t let Siva through to Atlassian because the user isn’t assigned to the enterprise application that handles SSO for Atlassian.

Atlassian has a KB article for this exact login error, and Microsoft documents the same cause for Entra SAML apps.

your company's SSO application for Atlassian is set to require assignment, and Siva isn't assigned to it, directly or through a group so the fix sits with whoever manages Entra ID at your company.

  1. Open Microsoft Entra admin center.
  2. Go to Entra ID > Enterprise apps.
  3. Open the application named in the error, in this case the one that looks like Atlassian_support_portal_saml_idp_spflow_external.
  4. Go to Users and groups.
  5. Select Add user/group.
  6. Assign Siva directly, or assign the group that gives access to that Atlassian SSO app.

If your org syncs groups to Atlassian through Atlassian Guard, the right group membership usually sorts out the Jira side at the same time. If not, then once he can sign in, John's step is the second half: confirm he actually has Jira access under admin.atlassian.com, Directory, Users.

One small thing: you may want to edit your post to mask your colleague's email address, since these threads are public and indexed.

Hope this helps.

 

0 votes
John Funk
Community Champion
June 10, 2026

Hi Bill,

That's a pretty horrible message. But if I get the gist of it, the user exists and you added them to a project, but they don't currently have a Jira license, i.e. they are not in a group which has access to Jira. You need to go to Settings > User Management, search for the user and click on them. Then you need to grant them User access to Jira. 

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
TAGS
AUG Leaders

Atlassian Community Events