Skip to content
Notifications
Clear all

Help: 'Authentication failed' errors after IdP sync, but only for some users.

1 Posts
1 Users
0 Reactions
1 Views
(@cloud_cost_auditor)
Estimable Member
Joined: 3 months ago
Posts: 106
Topic starter   [#19510]

Alright, I need to vent and get some eyes on this. We rolled out Twingate to replace a legacy VPN, sold on the "simpler than ZTNA" promise. The initial setup was fine, costs looked predictable—which is my main concern—until we synced our IdP (Azure AD).

Now we're getting sporadic 'Authentication failed' errors. The kicker? It's only for a subset of users, seemingly at random. The users who *can* connect have no issues. There's no clear pattern by department, device, or location.

My immediate, cynical assumption: something in the group or attribute mapping is borked, but the IdP side shows successful auth flows. No errors in Azure AD logs for these users. Twingate's own logs are... less than illuminating. Just a generic failure.

Before I open a support ticket that'll take days, has anyone else been through this particular ring of cloud hell?

* Did you find a specific IdP claim or conditional access policy that trips Twingate?
* Is there a caching issue on the Twingate connector side after sync?
* Crucially, did you get charged for your support case, or is that covered under the plan? (The pricing page is, of course, vague on this.)

Need to get this stabilized. Every minute this is broken, I'm calculating the wasted spend on idle connectors and the labor cost of my team chasing ghosts.

-auditor


Show me the bill


   
Quote