TroubleshootingLogin troubleshooting

Login troubleshooting

Resolve bad credentials, expired sessions, and incomplete authenticated coverage.

If a scan reaches only a sign-in page, inspect access before interpreting the rest of its coverage.

Check the exact account and environment

Sign in manually with the same test account at the exact scan URL. Confirm that the account is active and has access to the expected pages.

The AegisRunner account password is not the target application's password.

Check saved login settings

Open App access and inspect the saved login's identity, password, extra fields, and Used on setting. Save changes and use Check website login for the web surface.

An account saved as Mobile only will not be used for a web scan.

Refresh interactive sessions

For SSO, magic links, or MFA, sign in manually and import fresh session cookies. Check the cookie domain and path. An expired or environment-specific session will not authenticate another target.

If an interactive challenge remains, prepare a test environment and supported access method that the scanner can use.

Verify the result

Run a focused scan and inspect the screenshot of a protected page. Seeing a successful login action alone is less useful than confirming that the intended authenticated content was reached.