Skip to main content

Troubleshoot authentication and SSO login issues

Resolve common login failures in COINS ERP+, including account lockouts, forgotten credentials, Azure Active Directory SSO errors and two-factor authentication issues.

COINS ERP+ supports several login methods — standard password login, Azure Active Directory (AAD) SSO, AAD Login and two-factor authentication. This article helps you identify which method is in use and resolve the most common failures for each.

📌Note: Understanding which login method your organisation uses is the first step in diagnosing any login issue. If you are unsure, contact your system administrator before working through the steps below.

Login method

What it does

Compatible with 2FA?

Standard password login

Users log in with their COINS ERP+ user ID and password.

Yes

AAD SSO (full single sign-on)

Users log in with their Microsoft account and are authenticated into both COINS ERP+ and Microsoft apps. Users already signed into Microsoft are taken directly into COINS ERP+.

No — 2FA is not compatible with AAD SSO.

AAD Login

Users enter their COINS ERP+ user ID and their AAD (Microsoft account) password at the COINS login screen. This logs them into COINS ERP+ only — not into Microsoft apps.

Yes — 2FA pass code is still required if enabled.

Two-factor authentication (2FA)

A pass code is sent to the user's registered SMS or email address in addition to their primary login credentials.

Only with standard password or AAD Login — not with AAD SSO.


Account locked after failed login attempts

A COINS Construction Cloud (CCC) account is automatically locked for ten minutes after three consecutive failed login attempts. An error message appears after each failed attempt, and after the third attempt the account lock message is displayed. An email is also sent automatically containing the time at which the account will be unlocked.

Wait for the automatic unlock

After ten minutes, the account is unlocked automatically. If you remember your correct credentials, you can log in again immediately after the lockout period ends.

Unlock the account immediately (administrator)

  1. Log in to COINS ERP+ with administrator credentials.

  2. Go to System, then select User Maintenance.

  3. Click User Workbench.

  4. Search for the affected user by username.

  5. Click the folder icon next to the user's name to open their profile.

  6. Find the Account Locked field and untick the Account Locked checkbox.

  7. Click Save to apply the change.

  8. Ask the user to log in again with their correct credentials.

📌Note: If the user has forgotten their password as well as being locked out, reset the password first (see below), then unlock the account before asking them to log in.


Forgotten password or username

Self-service password reset

If your administrator has enabled the Forgot Password option (PWDRESET parameter set to Y), users can reset their own password from the login screen.

  1. On the web login screen, click the Forgotten Password? link. On the mobile login screen, tap the Forgot Password? link.

  2. Enter your username and follow the instructions in the password reset email.

Admin password reset

  1. Log in to COINS ERP+ with administrator credentials.

  2. Go to System, then select User Maintenance.

  3. Click User Workbench.

  4. Search for the affected user and click their user ID.

  5. Click the arrow icon next to Set User Password.

  6. Enter and confirm the new password, then click Next.

  7. Communicate the new password to the user securely.

For full steps and screenshots, see How do I unlock/reset user passwords?


AAD SSO not working

If users are unable to log in via Azure Active Directory single sign-on, work through the following checks.

Confirm 2FA is not enabled alongside AAD SSO

Two-factor authentication is not compatible with AAD SSO. If 2FA is enabled in your COINS ERP+ environment and AAD SSO is also configured, users will not be able to complete the SSO login flow. Your administrator should confirm which authentication method is intended and disable one accordingly.

Confirm the correct login method is being used

There are two separate AAD-based login options that are sometimes confused:

  • AAD SSO (full single sign-on) — authenticates into both COINS ERP+ and Microsoft apps. Users who are already signed into their Microsoft account are taken directly into COINS ERP+.

  • AAD Login — uses the AAD password at the COINS login screen but only logs into COINS ERP+. This is not full SSO.

Confirm with your administrator which method is configured in SY Parameters before troubleshooting further.

Check the user's Microsoft account status

  1. Confirm the user's Microsoft account is active and not locked in Azure Active Directory.

  2. Ask the user to sign in to another Microsoft application (such as Outlook or Teams) to verify their Microsoft account credentials are working.

  3. If the Microsoft account is working but COINS ERP+ SSO still fails, check that the user's COINS ERP+ user ID matches the account linked in the AAD app registration.

  4. If the issue affects multiple users simultaneously, check the Azure AD app registration and the AAD parameters in SY Parameters for recent configuration changes.

⚠️Important: Changes to the AAD app registration in Azure Portal or to AAD-related SY Parameters should only be made by a system administrator. Incorrect configuration can prevent all users from logging in. See Configuring AAD and Setting Up AAD Single Sign-On for the full configuration reference.


Not receiving the two-factor authentication pass code

If a user is not receiving their 2FA pass code, check the following.

  1. Confirm the correct SMS number or email address is registered on the user's account in User Maintenance.

  2. Ask the user to check their spam or junk folder if the pass code is sent by email.

  3. If the registered contact details are incorrect, an administrator can update them in User Maintenance before the user attempts to log in again.

  4. If the pass code is being sent but is expiring before the user can enter it, ask the user to request a new code and enter it promptly — pass codes are time-limited.

  5. Confirm that 2FA has not been accidentally enabled alongside AAD SSO. If AAD SSO is configured, 2FA should be disabled.


Newly provisioned user cannot log in

If a new user account has been created but the user cannot log in, work through the following checks.

  1. Confirm the user is entering the correct username — new users sometimes confuse their email address with their COINS ERP+ user ID.

  2. Confirm a password has been set for the account. New accounts may require an administrator to set an initial password via User Workbench before the user can log in.

  3. Check that the Account Locked checkbox is not ticked on the new user's record — this can sometimes be set by default depending on your system configuration.

  4. If your environment uses AAD SSO, confirm the new user's Microsoft account has been granted access to the AAD app registration in Azure Portal.

  5. Check that the user has the function access rights required to log in to the relevant module or screen. See How function access works for guidance.


Raise a support ticket

Raise a support ticket if:

  • An account remains locked after ten minutes and cannot be unlocked by an administrator.

  • AAD SSO is failing for multiple users and the Azure AD app registration and SY Parameters have been confirmed as correct.

  • A 2FA pass code is not being delivered and the registered contact details are confirmed as correct.

  • A newly provisioned user cannot log in after all configuration checks have been completed.

Include the username affected, the login method in use (standard, AAD SSO, AAD Login or 2FA), the exact error message displayed and the steps already completed.

Did this answer your question?