Signing in to the console fails
Windows sign-in
Section titled “Windows sign-in”| Symptom | Fix |
|---|---|
| The browser asks for a password | Add the console’s address to the Local Intranet zone (Internet Options › Security, or Group Policy). |
| Not allowed after signing in | The user is not in the administrators or viewers groups (AdminGroups, ViewerGroups). Group changes need a new Windows sign-in. |
| A local administrator is refused on a non-domain server | Local accounts lose BUILTIN\Administrators over the network: list the user by name (SERVER\alice). |
| The history tab is missing | The user is not in HistoryGroups (or an administrator). |
An identity provider
Section titled “An identity provider”| Symptom | Fix |
|---|---|
| The provider says the redirect URI is wrong | Register https://<the address users open>:5080/signin-oidc at the provider. |
| Signed in, but not allowed | The token has no group or role claims matching the settings: add the groups claim (or app roles) to the token, and check OidcRoleClaims and the group values. |
| The wrong user name | Change OidcNameClaim. |
Local accounts
Section titled “Local accounts”| Symptom | Fix |
|---|---|
| Locked | Five wrong passwords or codes lock an account for 15 minutes. An administrator can reset its password, which lifts the lock. |
| The first password is lost | It is in initial-admin-password.txt in the central service’s data folder until changed. |
| Lost the authenticator app | An administrator removes the account’s two-factor sign-in under Configuration › Users; the user sets it up again. |
| Lost a device with a passkey | An administrator removes the account’s passkeys under Configuration › Users (its sessions end too); the user signs in with the password and adds passkeys again. |
| Sign in with a passkey is missing, or says passkeys need https | Open the console over HTTPS (or on localhost): browsers offer passkeys only there. |
| The passkey is for another site | Passkeys are tied to the address they were made at: open the console at that address (the same host name), or add a passkey at this one. |
| The passkey did not verify the user | Set up a PIN, fingerprint or face on the device (or the security key’s PIN). |
