If a newly added user sees SSO login failed: This account was locked, the user is usually not active yet, even if the user was already added in the identity provider (IdP). Typically, the user is still in the Invited state, so Bloomreach doesn't consider the account active for SSO login.
Important: This article applies when your organization uses SSO authentication only. In that setup, Bloomreach verifies the user through SSO, but you still manage roles and user access in Bloomreach, and users must be invited into the application.
Troubleshooting steps
Go to Administration and locate the affected user.
Check the user status.
If the status is Invited, resend the invitation.
Make sure the user can access that mailbox and accept the invitation.
If the latest invitation is older than 7 days, ask the admin to resend it, because older invitations may no longer be valid.
Check your inbox and your spam, junk, promotions, and trash folders for the new invitation email.
Ask the user to try SSO again after the invitation is accepted.
If the user has already accepted the invitation and still sees the error, resend the invitation and ask them to accept it again.
If you use SSO authorization
If SSO authorization is enabled, this invite-based fix does not apply.
In that case, review the user's role mapping and identity provider configuration, because permissions are managed in the identity provider, not in Bloomreach.
For more information, read Unified SSO administration.