Skip to content

Signing in to the console fails

Symptom Fix
The browser asks for a password Add the console’s address to the Local Intranet zone (Internet Options › Security, or Group Policy).
Not allowed after signing in The user is not in the administrators or viewers groups (AdminGroups, ViewerGroups). Group changes need a new Windows sign-in.
A local administrator is refused on a non-domain server Local accounts lose BUILTIN\Administrators over the network: list the user by name (SERVER\alice).
The history tab is missing The user is not in HistoryGroups (or an administrator).
Symptom Fix
The provider says the redirect URI is wrong Register https://<the address users open>:5080/signin-oidc at the provider.
Signed in, but not allowed The token has no group or role claims matching the settings: add the groups claim (or app roles) to the token, and check OidcRoleClaims and the group values.
The wrong user name Change OidcNameClaim.
Symptom Fix
Locked Five wrong passwords or codes lock an account for 15 minutes. An administrator can reset its password, which lifts the lock.
The first password is lost It is in initial-admin-password.txt in the central service’s data folder until changed.
Lost the authenticator app An administrator removes the account’s two-factor sign-in under Configuration › Users; the user sets it up again.
Lost a device with a passkey An administrator removes the account’s passkeys under Configuration › Users (its sessions end too); the user signs in with the password and adds passkeys again.
Sign in with a passkey is missing, or says passkeys need https Open the console over HTTPS (or on localhost): browsers offer passkeys only there.
The passkey is for another site Passkeys are tied to the address they were made at: open the console at that address (the same host name), or add a passkey at this one.
The passkey did not verify the user Set up a PIN, fingerprint or face on the device (or the security key’s PIN).