Users are facing login issues on Microsoft To Do, Planner, and SharePoint mobile applications.

Jino Rose K G 0 Reputation points
2026-01-14T16:36:48.83+00:00

Microsoft 365 apps can be accessed through a web browser using External Identity (Google Workspace) login without any issues. However, we are facing problems when logging in through mobile applications.

We are using Google Workspace as the external Identity Provider (IdP). Using Google credentials, users are able to log in successfully through a browser. At the same time, mobile applications are unable to log in, except for Word and Excel.

Additionally, when a To Do task list is shared with team members, they are unable to join using the shared link. An error message such as “Cannot join” is displayed on their side. However, the list owner receives a notification stating that the member has joined successfully, even though the shared tasks do not appear for the member.

We are looking for a solution to resolve these issues.

Microsoft 365 and Office | Microsoft To Do | For education
0 comments No comments

4 answers

Sort by: Newest
  1. Anonymous
    2026-01-15T23:04:17.1533333+00:00

    Hi @Jino Rose K G

    Thank you for confirming that your tenant is using a SAML-based (Direct Federation) identity provider and that the issue is affecting all users. That information helps focus the next steps and configuration review.

    Based on general best practices for SAML-based single sign-on (SSO) and the details you’ve provided, here are effective authentication method guidance, configuration checks, and actions you can take to validate or adjust your SAML setup.

    When configuring and troubleshooting SAML-based SSO, there are several key components and steps to verify. Below is a consolidated reference based on standard SAML SSO setup and troubleshooting guidance:

    1. Verify SAML Metadata and Endpoints

    Ensure that the metadata exchange between the Identity Provider (IdP) and Service Provider (SP) has been completed correctly:

    • The IdP metadata (including Entity ID, SSO login URL, and signing certificates) must be imported into the SP configuration.
    • The SP metadata (Entity ID and Assertion Consumer Service (ACS) URL) must be imported into the IdP configuration. ()

    Incorrect or mismatched metadata values are a common cause of assertion validation and login failures, so these fields must match exactly between both sides.

    1. Confirm Assertion Attributes and Claims

    SAML assertions must include the correct attributes and claims that Microsoft 365 expects, including:

    • A valid NameID format (often mapped to the user’s email or UPN)
    • Matching email or username attributes between the SAML assertion and Microsoft 365 user accounts If the assertion lacks required claims or the attribute mapping does not match exactly, the service may accept the browser login but fail on backend validation required by mobile apps or shared services.
    1. Validate Certificates and Signature
    • Ensure that the IdP signing certificate is current and uploaded into the SP configuration.
    • Confirm that the SP trusts that certificate and that signature validation is enabled correctly.

    Expired or mismatched certificates can result in tokens that appear valid in some contexts but are rejected in others.

    1. Check Clock Synchronization

    SAML assertions contain validity timestamps (NotBefore and NotOnOrAfter). If the clocks on the IdP and SP systems are not synchronized (for example due to NTP drift), assertions can be rejected as invalid. 

    1. Enable Logging for Debugging
    • Turn on authentication and SAML logs on both the IdP and SP.
    • Tools such as SAML tracer extensions for browsers can help inspect SAML flows and identify assertion contents or errors. 

    This is especially helpful to confirm whether the assertion sent from the IdP contains the expected attributes and that the SP is interpreting them correctly.

    To move forward with the issue, please try these steps:

    1. Coordinate with your IT administrator to review the SAML metadata, assertion claims, certificates, and time synchronization settings based on the checklist above.
    2. If there are discrepancies in metadata or attributes, update the configuration and test the SSO flow again.
    3. Once these checks are complete or if the issue persists, your IT administrator should open a Microsoft Support ticket from the Microsoft 365 admin center. This allows Support to review tenant logs and identify any service-specific behaviors impacting mobile authentication or Microsoft To Do sharing.

    For more information on configuring and troubleshooting SAML based SSO, please refer to this article: How do I configure and troubleshoot SAML-based Single Sign-On (SSO)? – Sys Articles

    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make sure that you completely understand the risk before retrieving any suggestions from the above link.

    I hope this information is helpful. Please follow the steps above and let me know if it works for you. If not, we can continue working together to resolve the issue.  

    Thank you for your patience and understanding. If you have any questions or need additional assistance, please don’t hesitate to reach out so I can continue to support you. If you found the response useful, please consider marking it as accepted, as this may help other community members who are looking for similar guidance.  

    I look forward to continuing the conversation.  

    Was this answer helpful?


  2. Jino Rose K G 0 Reputation points
    2026-01-15T07:23:43.8866667+00:00

    Hello Jay,

    Thank you for your quick response.

    We are using a SAML-based (Direct Federation) identity provider.

    This issue is affecting all users, not just a few.

    Additionally, could you please advise which authentication method is more effective and recommended for both browser-based and mobile app-based applications?

    Also, could you please explain the configuration steps for the recommended method, so that I can recheck and confirm that the configuration we have implemented is correct?

    Thank you.

    Was this answer helpful?

    0 comments No comments

  3. Anonymous
    2026-01-14T21:14:59.95+00:00

    Hi @Jino Rose K G

    Welcome to Microsoft Q&A forum. 

    Thank you for reaching out and for clearly describing the issues you are experiencing. We understand how challenging it can be when access works in a browser but becomes inconsistent in mobile applications, or when shared task lists do not behave as expected. We appreciate you bringing this to our attention. 

    To ensure we investigate this accurately and avoid making assumptions about your environment, we will need some additional information from your IT administrator. Microsoft supports more than one method to integrate Google Workspace with Microsoft Entra, and the behavior you are seeing can vary depending on how this integration is configured. 

    Please ask your IT administrator to help confirm the following: 

    1. Google Workspace federation method 
    • Whether Google Workspace is configured as:  
      • A built-in Google external identity provider, or 
      • A SAML-based (Direct Federation) identity provider 
    1. Impact scope 
    • Whether all Google-federated users are affected or only specific users 

    While this information is being gathered and reviewed, the following workarounds may help reduce the impact: 

    1. Use Microsoft 365 via a web browser 

    Accessing Microsoft 365 applications through a browser is currently the most consistent option when using Google Workspace sign-in, including access to Microsoft To Do and shared task lists. 

    1. Access Microsoft To Do through the web instead of mobile apps 

    For shared lists, using the web version of Microsoft To Do may allow users to view and manage tasks more reliably than the mobile application. 

    1. Use Word and Excel mobile apps where needed 

    Since Word and Excel mobile apps are signing in successfully, they can continue to be used for document-related workflows while other apps are affected. 

    The best next step would be to have your IT administrator open a support ticket with Microsoft via the admin center. A technical support engineer can then initiate a remote session, review backend settings, and run diagnostics. If needed, they can escalate the case to specialized engineering teams who are well-equipped to perform advanced troubleshooting and provide targeted solutions.  

    As moderators, our primary goal is to provide helpful guidance and support through general troubleshooting steps. While we don’t have access to internal systems or administrative tools required to resolve account-specific or backend issues, we truly appreciate your understanding of these limitations. We genuinely hope the information we share helps point you in the right direction, and we're always here to assist as much as we can within our scope.  

    For guidance on how to request support in the admin center, please refer to: Get support - Microsoft 365 admin.      

    I hope you found the answer helpful, and we would greatly appreciate it if you could mark it as accepted. This helps highlight the solution for others who may be searching for similar information in the community. Your contribution not only supports fellow users in finding the right guidance more quickly, but also helps build a more resourceful and collaborative space for everyone. 

    Thank you for your kindness and contributions to the forum.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment". 

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.     

    Was this answer helpful?

    0 comments No comments

  4. AI answer

    2026-01-14T16:37:02.5866667+00:00

    Users experiencing login issues with Microsoft To Do, Planner, and SharePoint mobile applications while using Google Workspace as an external Identity Provider (IdP) may encounter several challenges. Here are some potential causes and troubleshooting steps:

    1. Embedded Web-View Sign-In Support Deprecation: Starting September 30, 2021, Google deprecated embedded web-view sign-in support. If your mobile applications are using embedded web views for authentication, this could be causing the login issues. It is recommended to modify your apps to use the system browser for sign-in instead.
    2. Authentication Tokens: If users are able to log in through a web browser but not through mobile applications, it may be related to invalid or mismatched authentication tokens. Ensure that users are signing in under the same user context as their signed-in Windows session, especially on shared devices.
    3. Application-Specific Issues: Since you mentioned that Word and Excel are functioning correctly, it may be worth checking if there are specific configurations or permissions required for To Do, Planner, and SharePoint that differ from those for Word and Excel.
    4. Sharing Issues with To Do Task Lists: The error message stating "Cannot join" when team members try to access shared task lists could indicate a permissions issue. Ensure that the shared task lists are correctly configured to allow access to all intended members. It may also be beneficial to check if the members have the appropriate licenses assigned and that their accounts are enabled for sign-ins.
    5. General Troubleshooting Steps:
      • Verify that the users' accounts are not locked out and are enabled for sign-ins.
      • Ensure that the users' passwords are not expired and that multifactor authentication is not blocking access.
      • Check any Conditional Access policies that might be affecting access to these applications.

    By addressing these areas, you may be able to resolve the login issues and improve the sharing functionality within Microsoft To Do.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.