Overview
This article helps you find out why a new user cannot log in to SalesScreen, and how to fix it.
The article is for Company Admins and User Admins who create users and send login information. Some steps can be done by the affected user.
Start by checking the user's status under Manage › Users. Most login problems are solved there.
Who can do this?
Action | Required access |
Check user status and resend login information | Company Admin or User Admin |
Generate an invite link or change a user's password | Company Admin or User Admin |
Activate a pending user | Account Owner, Company Admin or User Admin |
Add licenses | Account Owner |
Reactivate a deactivated user | Company Admin or User Admin |
Enable SSO providers, Force login with SSO and Force Two-Factor Authentication | Account Owner or Company Admin |
Assign users to the SalesScreen app in Okta | Your company's Okta admin |
Set up or remove Okta SSO | SalesScreen Support, together with your IT admin |
Set a password, set up two-factor authentication or log in with SSO | The affected user |
Which plans include this?
User login, login information, two-factor authentication and SSO are available on all plans.
Requirements
Before you start, make sure that:
You have Company Admin or User Admin access.
The user has been created in SalesScreen.
You know the email address the user should log in with.
You know whether your company uses password login, SSO or both.
When this matters
Use this article when a new user:
Says they never received a login email
Gets an error or message when trying to log in
Has a login link that no longer works
Cannot set a password
Is asked to set up two-factor authentication and gets stuck
Tries to log in with Google, Microsoft, Salesforce or Okta, and it fails
Is asked for a password even though your company uses Okta
How it works
A user can only log in when all of these are true:
Requirement | What it means |
The user is active | The user is on the Active tab, not Pending or Deactivated |
The user has login access | The user has set a password through the login email or invite link, or logs in with SSO |
The email address matches | The user logs in with the email address registered in SalesScreen |
The login method is allowed | Password login is allowed, or the user's SSO provider is enabled for your company |
Two-factor authentication is set up, if required | If your company forces two-factor authentication, the user must complete the setup |
Pending users cannot log in
If there are no available licenses when a user is added, the user is added as Pending. A pending user cannot log in. When the user tries, SalesScreen shows a message asking them to contact an administrator.
The user cannot activate the account themselves. An admin must activate the user when a license is available.
Login links and invite links expire
There are two ways to give a user access:
Method | How it works | How long the link works |
Login information email | SalesScreen emails the user a link for setting a password | Expires after a certain time |
Invite link | You generate a link and send it to the user yourself, for example in Teams, Slack or a text message | Expires after 24 hours |
If a link has expired, send a new one.
Passwords must have at least 12 characters
A password shorter than 12 characters is rejected. Some password managers and auto-fill tools create shorter passwords.
SalesScreen may also show a warning if the password has been part of a previous data breach. The user can still continue, but should choose another password.
Forced two-factor authentication
If Force Two-Factor Authentication is turned on for your company, users who log in with a password must set up two-factor authentication the first time they log in. Users who log in with SSO are not asked to set up two-factor authentication.
SSO uses the email address to match the user
When SSO is enabled, SalesScreen matches the email address from the SSO provider with the email address in SalesScreen. If the email addresses are different, the login does not work.
An SSO provider must be enabled for your company before users can log in with it. If Force login with SSO is on, users must log in with one of the enabled SSO providers, and password login is not available.
Logging in with Okta
Okta SSO is set up together with SalesScreen. Your IT admin creates the SalesScreen app in Okta, and SalesScreen completes the setup. After setup, Okta is shown under Manage › Settings › Security.
The user must be assigned to the SalesScreen app in Okta.
The first time, the user must log in by clicking the SalesScreen app in Okta, or by using your company's direct Okta login link.
After the first login, the user can also choose Okta on the normal login page and enter their email address.
The email address in Okta must match the email address in SalesScreen.
How to find and fix the problem
Step 1: Check the user's status
Click Manage in the bottom-left corner.
Under Company, click Users.
Find the user on the Active, Pending or Deactivated tab.
If the user is on | Do this |
Pending | Activate the user and select a team. If there are no available licenses, ask an Account Owner to add licenses first |
Deactivated | Reactivate the user. Reactivation requires an available license |
Active | Continue with Step 2 |
The Last Login column shows Never logged in for users who have not logged in yet.
Step 2: Check the email address
Click the user's name to open Edit Profile.
On the Profile tab, check that the email address is correct and has no typos.
If it is wrong, correct it and save.
Step 3: Send the login information again
Do this if the user did not receive the email, or if the link has expired. Skip this step if your company only uses SSO.
Go to Manage › Users.
Check the box next to the user.
Click Email Login Information/Send reset password via email.
Ask the user to check the spam or junk folder if the email does not arrive.
If the login information was sent before the user's email account was created, send it again.
To send login information to several users at once, click Send invites on the Users page. You can send invites to all users that match your current filter, or only to users who have not logged in yet.
Step 4: Send an invite link directly (if the email does not arrive)
If the user still does not receive the email, you can send the link yourself:
Go to Manage › Users and click the user's name.
In Edit Profile, click the Security tab.
Under Invite Link, click Generate invite link.
Click Copy invite link.
Send the link to the user in Teams, Slack, a text message or another channel.
The invite link expires after 24 hours.
Step 5: Check the password
If the user's password is rejected, check that it has at least 12 characters. Ask the user to count the characters, or to choose a password that clearly meets the minimum.
If needed, you can set a new password for the user. In Edit Profile, click the Security tab and click Change Password.
Step 6: Check two-factor authentication
If the user is asked to set up two-factor authentication after setting a password, your company has turned on Force Two-Factor Authentication. Ask the user to complete the setup.
To check the setting, go to Manage › Settings › Security.
Step 7: Check the login address and method
Password login: the user logs in at app.salesscreen.com with the email address registered in SalesScreen.
SSO login with Google, Microsoft or Salesforce: the user logs in with the SSO provider your company has enabled. The email address at the SSO provider must match the email address in SalesScreen.
SSO login with Okta: the first time, the user logs in by clicking the SalesScreen app in Okta, or by using your company's direct Okta login link. If the user is asked for a password, ask your Okta admin to check that the user is assigned to the SalesScreen app in Okta.
To check which SSO providers are enabled, and whether Force login with SSO is on, go to Manage › Settings › Security.
Expected result
The user is on the Active tab.
The user receives the login email or invite link, sets a password with at least 12 characters and logs in at app.salesscreen.com.
If your company forces two-factor authentication, the user completes the setup at first login.
If your company uses SSO, the user logs in through the enabled SSO provider.
If your company uses Okta, the user logs in through the SalesScreen app in Okta or your company's direct Okta login link.
The Last Login column shows when the user last logged in.
Technical details
3.2.1 Data, fields or objects
Field or object | Description |
User status | Active, Pending or Deactivated |
Pending user | A user added without an available license. Cannot log in until an admin activates the user |
Last Login | Shows when the user last logged in, or Never logged in |
Login information email | An email with a link for setting a password |
Invite link | A link you generate and send to the user yourself. Expires after 24 hours |
Two-factor authentication | An extra login step. Required at first login if forced for your company |
SSO provider | Google, Microsoft, Salesforce or Okta, if set up for your company |
Force login with SSO | Setting that requires users to log in with an enabled SSO provider |
SalesScreen app in Okta | The app your IT admin creates in Okta. Users must be assigned to it to log in with Okta |
Direct Okta login link | Your company's own link for logging in to SalesScreen with Okta |
3.2.2 Configuration parameters
Setting | Where to configure it | Notes |
User status | Manage › Users › Active, Pending or Deactivated | Pending and deactivated users cannot log in |
Send login information | Manage › Users › select the user › Email Login Information/Send reset password via email | Sends a new link by email |
Send invites | Manage › Users › Send invites | Sends invites to all users that match the filter, or only to users who have not logged in |
Send login information when creating a user | The user creation form › Send login information to email | Sends the email as soon as the user is created |
Invite link | Manage › Users › the user › Edit Profile › Security › Generate invite link | Copy the link and send it yourself. Expires after 24 hours |
Change password | Manage › Users › the user › Edit Profile › Security › Change Password | Sets a new password for the user |
SSO providers | Manage › Settings › Security | A provider must be enabled before users can log in with it |
Force login with SSO | Manage › Settings › Security | Can only be turned on if at least one provider is enabled |
Force Two-Factor Authentication | Manage › Settings › Security | Users with password login must set up 2FA at first login. Does not apply to SSO logins |
Okta SSO | Set up in Okta, then completed by SalesScreen | Shown under Manage › Settings › Security after setup. Contact SalesScreen Support to set up or remove Okta SSO |
Okta app assignment | In Okta, managed by your Okta admin | Users must be assigned to the SalesScreen app in Okta |
3.2.3 Limits and behaviour
Area | Behaviour |
Pending users | Cannot log in. Shown a message to contact an administrator |
Login information email | The link expires after a certain time. Sending the login information again creates a new link |
Invite link | Expires after 24 hours |
Password length | At least 12 characters |
Password breach warning | Shown if the password has been part of a data breach. Does not block login |
Forced two-factor authentication | Applies to password login. Does not apply to SSO login |
SSO matching | The email address at the SSO provider must match the email address in SalesScreen |
SSO providers | Must be enabled by an Account Owner or Company Admin |
Force login with SSO | Users must log in with an enabled SSO provider |
Okta first login | Must be done through the SalesScreen app in Okta or your company's direct Okta login link |
Okta setup and removal | Done by SalesScreen. Okta cannot be turned off from Manage › Settings › Security |
Reactivation | Requires an available license |
3.2.4 Error codes and typical issues
Symptom | Likely cause | How to fix it |
The user sees a message to contact an administrator | The user is pending | Activate the user. Ask an Account Owner to add licenses if needed |
The user never received the login email | The email went to spam, the email address is wrong, the email was sent before the user's email account existed, or the email was never sent | Check spam and the email address, send the login information again, or send an invite link directly |
The login link or invite link does not work | The link has expired | Send the login information again, or generate a new invite link |
The password is rejected | The password is shorter than 12 characters | Choose a password with at least 12 characters |
The user sees a warning about the password | The password has been part of a previous data breach | Choose another password |
The user is asked to set up two-factor authentication after setting a password | Force Two-Factor Authentication is on | Ask the user to complete the two-factor setup |
The user set a password but still cannot log in | Wrong login address or email address, or your company uses SSO | Use app.salesscreen.com and the registered email address, or log in with SSO |
SSO login fails | The email address at the SSO provider does not match SalesScreen, or the provider is not enabled | Correct the email address in SalesScreen, or enable the provider under Manage › Settings › Security |
An Okta user is asked for a password | The user is not assigned to the SalesScreen app in Okta, or is not logging in through Okta | Ask your Okta admin to assign the user to the SalesScreen app. Then log in by clicking the SalesScreen app in Okta, or by using your company's direct Okta login link |
Okta login fails for a new user | The user is trying to log in from the normal login page before logging in through Okta for the first time | Log in by clicking the SalesScreen app in Okta, or by using your company's direct Okta login link |
Password login is not available | Force login with SSO is on | Log in with the enabled SSO provider |
The user was able to log in before but cannot now | The user has been deactivated | Reactivate the user from the Deactivated tab |
What if this doesn't work?
Check the following:
The user is on the Active tab.
The email address on the user profile is correct.
You have sent the login information again, or sent an invite link directly, and the link is less than 24 hours old.
The password has at least 12 characters.
The user has completed two-factor authentication, if your company requires it.
The user uses app.salesscreen.com, or the correct SSO provider.
For SSO, the email address at the SSO provider matches the email address in SalesScreen.
For Okta, the user is assigned to the SalesScreen app in Okta and logs in through Okta the first time.
If the user can log in but sees no data, the cause is not the login. See Why is a new user not showing in SalesScreen?
If the issue still is not resolved, contact SalesScreen Support and include:
The user's name and email address
The user's status: Active, Pending or Deactivated
Your login method: password, SSO or both, and which SSO provider
For Okta: whether the user is assigned to the SalesScreen app in Okta, and how the user tried to log in
Whether your company forces two-factor authentication
Whether the user received the login email or invite link
The exact error message the user sees, or a screenshot
Steps you have already tried
