Unable to log in to Hoxhunt?

Overview

You don't need to log in to Hoxhunt platform to report suspicious emails with Hoxhunt button. However, if you wish to access your profile details, training progress or check your current ranking on the leaderboard, you can log in to Hoxhunt Dashboard at https://game.hoxhunt.com. If you are an admin, you can access Hoxhunt Admin portal at https://admin.hoxhunt.com.

There are several ways to log in:

  • by reporting a Hoxhunt training email
  • by clicking the Hoxhunt button on an email not sent by Hoxhunt and choosing Go to dashboard in the right hand side panel that opens in your email inbox
  • via a verification code
  • via Single Sign-On (SSO)
NOTE
If SSO has been configured for your organization, logging in via a verification code is not possible; you will need to be added to the SSO configuration of the organization to log in via SSO.

 

Log in with a verification code

If your organization uses verification codes instead of SSO, sign in as follows:

  1. Navigate to https://game.hoxhunt.com/ or https://admin.hoxhunt.com/ and type in your email address.
  2. Select Send verification code.
  3. Open the email from Hoxhunt and enter the 8-digit code on the login page. Sign-in completes automatically once all digits are entered correctly.
Verification_code_login_page_request.png
Verification_code_login_page_enter.png
NOTE
Make sure you enter your email address correctly, and that you have user account in Hoxhunt - otherwise the verification code email will never arrive. The verification code is valid for 10 minutes. If it expires or you mistype it multiple times, select Didn't receive a code? Request a new one.

 

Log in via Single Sign-On (SSO)

If SSO has been configured for your organization, logging in to Hoxhunt is easy.

  1. Navigate to https://game.hoxhunt.com/ or https://admin.hoxhunt.com/ and type in your email address.
  2. SSO button with your organization's name will appear. Start the sign-in process by clicking the button.

If you cannot login, you may not have been added to SSO for your organization. Please reach out to your admin to troubleshoot this further.


Having trouble logging in?

I'm unable to log in via a verification code

I didn't receive the code email. Check your Junk and Other folders, and allow a few minutes for delivery. Make sure you entered your email address correctly; it must match the address in our records. For security, requesting a code for a non-existing account still looks successful, so a wrong address simply means no email arrives.

"Invalid or expired code. Please request a new code." The code is valid for 10 minutes and can be entered a limited number of times. Request a new code and enter the most recent one.

"Too many requests. Please try again later." Both requesting and entering a code are rate-limited. Wait a few minutes, then try again.

 

I'm unable to log in via SSO

NOTE: The instructions below are meant mainly for Entra ID SSO customers. If you are using AD FS SSO or Okta SSO, please contact Hoxhunt Support or your own IT Support for assistance.

 

I get redirected back to Hoxhunt login page

If you are using Chromium Edge web browser and the browser logged in to your M365/Entra account, make sure you are logged in to Edge browser with the same account you use to log in to Hoxhunt. Also make sure to close all other browser sessions that are logged in with some other M365/Entra account.

You can also check the URL for clues. "Organization not found" indicates you are trying to authenticate with a user account that is not allowed to log in to Hoxhunt.

 

If you are getting redirected back to Hoxhunt login page also with other web browsers (and your colleagues have a similar problem), then please contact Hoxhunt Support. This indicates your SAML certificate has expired and should be renewed.

You can also check the URL for clues. "Invalid signature" indicates the SAML certificate has expired.

 

I have an error code

If you receive an error code, please check the table below:

Error code Explanation

AADSTS700016Application with identifier 'https://app.hoxhunt.com/saml/consume/xxxxyyyyzzzz' was not found in the directory 'xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx'.

There is a misconfiguration. Please contact your IT support or Hoxhunt support.

AADSTS50105The signed in user 'xxxx.xxxx@xxxx.com' is not assigned to a role for the application 'yyyyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyyyy' (HoxHunt).

The user has not been added to the SSO sign-in list of approved users. Please ask your IT support to add you to the Hoxhunt SSO group in the correct Microsoft Entra ID tenant.
Read more: https://docs.microsoft.com/fi-fi/azure/active-directory/manage-apps/methods-for-assigning-users-and-groups

AADSTS75011Authentication method 'AAAAAA, BBBBBB' by which the user authenticated with the service doesn't match requested authentication 'CCCCCC, DDDDDD'.

There is a misconfiguration. Please contact Hoxhunt Support.
Read more: https://docs.microsoft.com/en-us/troubleshoot/azure/active-directory/error-code-aadsts75011-auth-method-mismatch

AADSTS650056: Misconfigured application. This could be due to one of the following: the client has not listed any permissions in the requested permissions in the client's application registration. Or, The admin has not consented in the tenant. Or, Check the application identifier in the request to ensure it matches the configured client application identifier. Please contact your admin to fix the configuration or consent on behalf of the tenant.

AADSTS650056: Misconfigured application. This could be due to one of the following: the client has not listed any permissions for 'AAD Graph' in the requested permissions in the client's application registration. Or, The admin has not consented in the tenant. Or, Check the application identifier in the request to ensure it matches the configured client application identifier. Please contact your admin to fix the configuration or consent on behalf of the tenant.

Make sure that URL taken from the "ACS URL (Entity ID)" field in Hoxhunt Admin Portal to the “Identifier (Entity ID)” field in Entra ID SSO app is correct.

The correct format is https://app.hoxhunt.com/saml/consume/...

Cloudflare timeout 524 page is displayed

Your organization's SSO certificate for Hoxhunt might have expired. Please contact your IT support for assistance.

 

I have another type of problem

If you don't receive any error code, please try the following tips:

  • Wait for a few moments and try again.
  • Ensure you have typed your email address correctly.
  • If you haven't used Hoxhunt before you may not yet have a Hoxhunt user account. Click on Hoxhunt button in your email client and complete the onboarding process. Then try logging in again via SSO.
  • If the problem persists, please contact your local IT support team for assistance. 

Was this article helpful?

35 out of 39 found this helpful

Have more questions? Submit a request