Access & Security
...
Microsoft Entra ID
Troubleshooting Entra ID Authentication
factry historian no reply address provided either the redirect uri is wrong, the baseurl is wrong or the factry historian was not restarted after the last change of the baseurl admin permissions needed a microsoft entra id administrator must grant permission for historian to receive login data from entra id this typically appears as a pop up requesting admin consent, with an option to “consent on behalf of the entire organization ” error on login missing privileges contact your system administrator if no group mapping is enabled in factry historian (see setting up entra id authentication in factry historian docid 8fvf2zgangaf70qy5yyec ) → you must manually add the user to a group in factry historian to grant privileges a user without privileges is not able to log in if group mapping is enabled in factry historian → verify the group mapping configuration, and if the user is part of the mapped group in entra id when group mapping is active, manually adding users to groups in historian will not work, group membership is managed entirely through entra id error aadsts50011 the redirect uri 'https //xxxx\ xxxx/api/auth/microsoft/callback' specified in the request does not match the redirect uris configured for the application the factry historian authentication base url does not match the redirect url configured in the entra id app registration learn more here https //aka ms/redirecturimismatcherror verify in the azure app registration – a incorrect redirect uri may have been saved e g a wrong historian base url or an incorrect authentication provider name was given in the uri in factry historian – if the authentication base url (general settings > authentication) was changed, but historian was not restarted, the new url was not applied yet restart factry historian via the {{cli}} or contact factry support grafana no reply address provided check that the redirect uris in microsoft entra id are correct (grafana requires two redirect uris) check that the root url in grafana ini is correct need admin approval this means an administrator must grant the necessary permissions to the grafana app in the microsoft entra id configuration whether this is required depends on your organisation’s entra id domain settings redirect uri issue in azure app registration, one or both redirect uris are incorrect root url issue in grafana, root url is misconfigured view root url in grafana via home > administration > general > settings , search for root url to change, edit file /etc/grafana/grafana ini on the server approval needed first login may need an azure admin to approve app access duplicate usernames if a local grafana user has the same username as the entra id user, login fails remove or rename the local user too many security groups users with >150 groups they belong to exceed request size use app roles instead of security groups don't spot your error? contact factry support