Common sign-in issues
User account has been locked from too many failed sign-in attempts.
The account uses password authentication, and runZero locked it after repeated incorrect sign-in attempts. Have your runZero administrator follow these steps:
- In the runZero console, visit the Team page.
- Select the locked account.
- Use the “Unlock user accounts” option in the “Reset” dropdown menu.
If you can’t reach an administrator, contact support@runzero.com.
Certificate information for single sign-on has expired and must be updated in order to sign in
Replace the expired SAML certificate configured for your runZero tenant:
- Get a new, valid certificate from your identity provider (for example, Okta or Google Workspace).
- Sign in to runZero with a superuser account that uses link-based or password-based authentication.
- Paste the new certificate contents into the “Certificate” field of the Identity provider settings page.
- To reach the “Certificate” field, open the Team page, then click the “SSO settings” button in the page header.
If you are the administrator for your account and can’t sign in at all, contact support@runzero.com and include the new certificate.
Invalid SAML response
Review the SAML configuration in your identity provider (for example, Okta or Google Workspace); the data it sent to the runZero console was in an invalid format. Implementing SSO covers runZero’s SAML SSO setup.
The information provided by your identity provider was incomplete or not valid.
Check that your identity provider is configured to send a valid Subject and NameID to the runZero console. Its response was missing one or more of the required assertion elements, Subject and NameID.
The email address {email address} is already in-use by an existing user account.
The email address your SSO identity provider sent already belongs to an account in a different runZero tenant. Change that account’s email address or delete the account, in any of these ways:
- Sign in to the runZero console with the email address from the error message and change the account’s email address to something different.
- Ask the administrators of the tenant where your email address is registered to delete your account from the Team page.
- Email runZero support at support@runzero.com and ask them to delete your existing account.
Once the email address is free, you can sign in with SSO.
The identity provider has provided an invalid NameID
Configure your identity provider (for example, Okta or Google Workspace) to send an email address in the NameID attribute, or ask your administrators to do so. The NameID it sent is not formatted like an email address, and the runZero console uses this attribute as your email address.