Troubleshooting
Start with the Sign-in Logs. They show whether a sign-in reached AuthCop, whether it worked, where it came from and which method was used.
A student can't sign in
Work through these in order.
- Is the student in AuthCop? Search for them on the Users page. If they're missing, they haven't synced from Microsoft Entra yet. Check the SCIM provisioning in Entra.
- Where are they signing in from? Check the country in the Sign-in Logs. Is it on the Blocked Countries list?
- Does a policy block them? Look at your access policies. Is there a Block policy that applies to them? A policy applies only when the student matches its groups and locations and time ranges. Empty groups or locations mean "all users" or "all locations".
- Does any policy apply to them at all? If none does, the Default policy blocks them. Check they are in the right groups, and that they are signing in from a location and at a time the policy covers.
- Do they have a method they can use? A policy may allow QR codes, but the student needs their own QR code for it to appear. Check their MFA Methods tab. Is the code expired, or does it have a start date in the future?
- Is the method turned on? Check MFA Methods.
While you sort it out, the student can ask a teacher for help if the Teacher method is allowed. See Teacher MFA requests.
A student lost their QR code card
- Open the student and go to their MFA Methods tab.
- Remove the old QR code, so nobody else can use the lost card.
- Select Add MFA Method, choose QR Code, and print a new card.
The QR code scanner doesn't work
- The browser must be allowed to use the camera. The sign-in page shows instructions for the student's browser.
- Check the camera isn't covered by a privacy shutter, and that a laptop camera switch isn't turned off.
- Hold the card flat and still, in good light.
I changed a setting but nothing happened
Changes to users, methods, policies, locations and blocked countries reach the sign-in page in the background. Wait a few minutes, then ask the student to start a new sign-in. A student already part-way through signing in keeps the rules they started with.
Teacher can't see a student's request
- Turn off My classes only, or clear the filters, on the Teacher MFA Requests page.
- Select Refresh Request List.
- The request may have expired. Ask the student to sign in again.
- The teacher needs the Teacher Request Reviewer permission (or a higher one). See Admin permissions.
A page is missing from the admin portal menu
You don't have permission for it, or the feature isn't turned on for your school. See Admin permissions.
Nobody can sign in to the admin portal
The admin portal certificate may have been regenerated without uploading the new one to Microsoft Entra, or it may have expired. See Entra configuration → Client certificate. Contact AuthCop support if you can't get in at all.
Nobody at the school can sign in (students)
- Check the AuthCop Verify Client Id on Entra configuration matches your external authentication method in Microsoft Entra.
- Check at least one Challenge access policy is enabled.
- Contact AuthCop support.
An import didn't work
Open the Import Logs and select Export Logs to see which rows had problems. Check the file names and column names match the CSV formats exactly.
Getting more help
If you're still stuck, contact AuthCop support. It helps to include:
- the student's username
- the date and time they tried to sign in
- what they saw on screen, or a screenshot