Skip to content
English - United Kingdom
  • There are no suggestions because the search field is empty.

What is an unresolved user?

An unresolved User is a User who has no valid way to log in to SpeakUp. They keep their account and data, but cannot sign in until an Administrator resolves their access.

Unresolved status is a safeguard. SpeakUp never silently removes a User's access, and SSO setup is never blocked. Users who would be left without a login path are flagged so an Administrator can decide how to handle them.

When a User becomes unresolved:

A User becomes unresolved in two scenarios:

Scenario 1 - IdP or email domain removed without a password invitation:
A User was authenticating via an Identity Provider. The Identity Provider or its email domain mapping is removed, but no password invitation is sent to the User. Because the User authenticated via SSO and has no valid password in SpeakUp, they become unresolved, even if password login is enabled for the organisation.

Scenario 2 - Previous password User whose domain is not covered when SSO is enabled:
A User was authenticating with a password. SSO is configured and enabled for the organisation, which automatically turns off password login. The User's email domain is not mapped to any Identity Provider, so they have no SSO path. When password login was disabled, their previous password was invalidated, and they become unresolved.

Re-enabling password login alone does not resolve these Users. Their previous password is no longer valid, they need to receive a new password invitation before they can log in again.

The check runs whenever:

How unresolved Users are surfaced:

  • Unresolved Users appear in the user overview with the status Unresolved.
  • The user overview can be filtered by Authentication method to show only Unresolved Users. 
  • A warning banner is shown at the top of the user overview when Unresolved Users exist, prompting you to take action.

What Unresolved Users see at login:

An Unresolved User who tries to log in sees an error message explaining that their account has no active authentication method and that they should contact their Administrator.

How to resolve Unresolved Users:

You have three options:

  1. Map the User's email domain to an Identity Provider: all Users in that domain are resolved automatically. Refer to How do I map email domains to an Identity Provider?
  2. Enable password login and send password invitations: enabling password login alone is not sufficient, since Unresolved Users have no valid password. You must also send them a password invitation so they can set a new one. To do this for all of them at once, filter the user overview by "Authentication method" to "Unresolved", then use "Invite users" to send password invitations to everyone in the filtered results. Refer to How do I enable password login alongside SSO?
  3. Disable the affected Users individually: removes their access entirely.

SSO setup is never blocked. You can complete configuration and handle Unresolved Users afterwards at your own pace. A User whose email address changes in the Identity Provider keeps access to their existing account automatically, since SpeakUp identifies them by a stable ID from the Identity Provider rather than by email.