Guides / AWS Console or Azure Portal sign-in stuck or looping
Last reviewed 5 Oct 2026
AWS Console or Azure Portal sign-in stuck or looping
Stuck on AWS sign-in or the Azure portal spinner? Separate a cloud identity outage from SSO, MFA, browser cookies and Conditional Access.
The engineer needs the console. The browser spins on portal.azure.com, or AWS returns them to the sign-in form after MFA. Tickets arrive as "AWS is down" or "Azure is down". Both clouds have real incidents. Both also have a long list of local reasons a single session never becomes a working console.
Is the cloud identity plane down?
For AWS, open AWS Health / the Service Health Dashboard and our AWS status page — pay attention to the region you use and to IAM / sign-in notes when present. For Azure and the portal, check the Azure and Entra ID pages plus Service health. If both clouds fail for you at once, suspect the browser, extension, corporate SSL inspection or the IdP in front of both, not a simultaneous dual-cloud outage.
User-level checks
- Private window, extensions off. Password managers that auto-submit, ad blockers, and old cookies from a previous org cause a large share of console loops.
- Correct account type. AWS root user versus IAM user versus SSO (IAM Identity Center) are different entry URLs. Azure personal Microsoft accounts versus work or school accounts are different directories. Using the wrong door looks like a broken door.
- Try the other console. If Azure portal fails and entra.microsoft.com or a plain
login.microsoftonline.comprompt works, the portal front end or a blade is the problem, not your password. - MFA device. Hardware keys, Authenticator number matching, and AWS MFA virtual devices fail independently. Use a backup MFA method if your admin enrolled one.
- Another network. Some tenants restrict console access to corporate IP ranges. Home broadband then "breaks" Azure or AWS every evening.
Admin checks
- Federation / SSO. Many companies sign into AWS IAM Identity Center or the Azure portal through Okta or Entra. Debug the IdP first when everyone fails. See our Okta SSO guide if tiles die across apps.
- Conditional Access on Azure portal. Policies that require compliant devices or block legacy clients will stop the portal while Graph Explorer or CLI still work (or the reverse). Read the sign-in log for the failed portal attempt.
- AWS SCPs and permission boundaries. Sign-in can succeed while every blade shows Access Denied. That is authorisation, not an outage. Confirm the account, OU and role.
- Directory sync timing. A newly created Entra user or AWS Identity Center assignment can take a few minutes to appear. Waiting beats rebuilding the browser twice.
- Break-glass. Keep a cloud-native admin that does not depend on the corporate IdP so you can still open the console when SSO is the incident.
CLI versus browser
If aws CLI or Azure CLI works with the same credentials while the browser fails, focus on cookies, extensions and portal endpoints. If CLI fails with expired SSO tokens, refresh the session; do not rotate access keys as a first move.
Guest and B2B access
Contractors signing into your Azure portal as guests fail when the invite is pending, the guest redemption never finished, or Cross-tenant access settings block them. Check the guest user record in Entra before rebuilding their laptop. AWS cross-account roles need an external ID and a trust policy that still matches; an old role ARN in a runbook produces Access Denied after a clean sign-in.
Password managers
Saved passwords for the wrong AWS account alias or an old Microsoft tenant URL will replay forever in a loop. Create separate vault entries for root, IAM Identity Center, and each Azure tenant, and label them clearly.
When to escalate
Open a vendor case when Health dashboards show an incident affecting sign-in or the portal, or when many admins on different networks and browsers cannot reach the console while your IdP stays healthy. Include account/tenant IDs, region, timestamps and correlation IDs from the error page. For one laptop with a sticky cookie, clear the site data and move on.
Related status pages
Related guides
- Microsoft 365 sign-in loop or 'More information required'
- Okta SSO not working: outage, MFA, or account lockout?
- Conditional Access: device not compliant or not joining
FAQ
- Why is the Azure portal stuck on a spinner after sign-in?
- Often a blade or subscription filter problem, a browser extension, or Conditional Access after authentication. Try a private window, another browser, and check whether entra.microsoft.com loads. Admins should read the Entra sign-in log.
- AWS keeps returning me to the login page — is IAM down?
- Check AWS Health for your region. More commonly it is the wrong sign-in path (root vs IAM vs IAM Identity Center), MFA, or a corporate IdP in front of AWS SSO.
- Can Okta being down block both AWS and Azure consoles?
- Yes, if both use that Okta org for SSO. Confirm whether break-glass cloud-native accounts still work. If they do, the cloud is up and the IdP is the incident.
- Where are the official status pages?
- AWS Health at health.aws.amazon.com, Azure status via Microsoft's public status boards, and Entra ID / Microsoft 365 Service health for sign-in. Use our AWS, Azure and Entra pages as a shortcut.