| Products | Versions |
|---|---|
| Spotfire | All |
When a user tries to access the Spotfire dashboard on the browser, the user gets an error message, "You must accept the request for permissions to log in to Spotfire."

Log entries confirm this issue:
This indicates that while Spotfire attempts authentication via OpenID Connect, the IdP denies access because the user lacks the required role or assignment to the Spotfire application. Common reasons for this include changes in group membership or automated clean-up policies that unassign inactive users from applications.
Users may encounter an "access denied" error when attempting to access Spotfire dashboards if they are not assigned to the Spotfire application group within the configured Identity Provider (IdP), such as Okta, Azure Intra ID, etc. This issue is resolved by ensuring the user has the necessary role assignment in the IdP.
Doc: Configuring OpenID Connect.
KBA: KB0075873 How to configure OpenID Connect authentication with Okta on the TIBCO Spotfire Server.
KBA: KB0079218 How to configure OpenID Connect authentication with Google on the TIBCO Spotfire Server.
KBA: KB0075046 How to configure OpenID Connect authentication with Azure on the TIBCO Spotfire Server.