This guide explains the most common Zone Employee Portal (ZEP) access problems, why they happen, how they were resolved, and the practices that help prevent them.
Before you begin
Confirm whether the user signs in with a password and 2FA or through single sign-on (SSO). Do not repeatedly resend invitations or reset passwords until you confirm the employee record, login email, and authentication method.
Quick checks
Use the email address currently shown on the employee record in NetSuite and ZEP.
Check spam, junk, quarantine, blocked-sender lists, mailbox rules, and forwarding rules for ZEP messages.
Allow messages from no-reply@mail.employee.zoneandco.com.
Try a private browser window or another supported browser.
If using SSO, confirm that the user is assigned to the ZEP application in the identity provider.
Check the Integration Queue for employee- or user-related integration errors. These errors may block synchronization between NetSuite and ZEP and prevent a user from being created, updated, invited, or granted access.
Error and solution reference
1. “I did not receive the invitation, login code, or password-reset email”
Problem: An employee cannot activate or access ZEP because an invitation, 2FA code, or password-reset message is missing. This may affect one user or many users.
Likely causes:
The message was filtered into spam, quarantine, or another folder.
A mail rule or security gateway blocked the sender.
The recipient address was placed on the email provider’s suppression list after a delivery failure or spam complaint.
The employee has not yet been invited or registered. Being present in the employee list does not create a ZEP login.
Mailbox host temporarily rejected ZEP messages.
Resolution:
Search all mailbox folders and quarantine areas for ZEP messages.
Mark a ZEP message as Not spam, add the sender to the allowed list, and review mail rules.
Confirm that the mailbox exists and can receive external messages.
In ZEP, check Active Users or the employee record. If the employee is not registered, select Invite.
If the address is suppressed because of a delivery rejection or complaint, Support can remove it after the mailbox is confirmed and ZEP messages are allowed.
After the address is cleared, invite the employee again.
Important: Do not repeatedly resend invitations to a nonexistent, blocked, or invalid mailbox. Repeated delivery failures can cause the address to be suppressed again.
Resolved examples: Addresses affected by “Recipient address rejected: Access denied,” “User unknown,” and spam complaints were removed from suppression after customers verified the mailboxes and allowed ZEP messages. A separate Microsoft delivery incident affecting Hotmail, Outlook, and Live addresses was resolved through email-provider configuration changes.
2. “Failed to reset your password, please check that your email is correct”
Problem: The user enters an email address on the password-reset page but receives the error instead of a reset link.
Likely causes:
The user was created through SSO and has no password.
The employee has not completed registration.
The user is entering an old email address.
The employee record and the ZEP login are not linked correctly after an SSO rollout or account change.
Resolution:
Confirm the exact email on the current NetSuite employee record.
Check whether the user appears in ZEP > Administration > Active Users.
If the user was created through SSO only, password reset will not work until a password-based login is created or enabled.
If the employee has not registered, select Invite on the employee record and complete registration.
If the email changed, use the new email for both login and password reset. The existing password normally remains unchanged.
Resolved examples: Users created through SSO were given a password-based login or had the SSO-only login removed so they could be invited again. Unregistered employees were invited from their employee records.
3. “All roles for user require Employee record”
Problem: The user cannot sign in because the login is associated with an old, missing, or duplicate employee record.
Cause: A rehire or duplicate record created two employee records with the same email, or the new employee record was not connected to the existing login.
Resolution:
Identify the active employee record that should provide access.
Remove the duplicate email from any obsolete record.
On the current employee record, select Invite to connect it to the existing login.
Disable MyPay Access on the old employee record in NetSuite.
If the association remains incorrect, contact Support to remove the old link and reconnect the login.
Correct practice: For rehires, disable the old employee record before connecting the login to the new one. Avoid having two active records with the same email.
- On the old employee record in NetSuite, remove the email address, set MyPay Access to False, and mark the record as Inactive.
- On the new employee record in NetSuite, enter the email address.
- Set MyPay Access to True to connect the new record to the Zone Employee Portal.
4. Login opens the wrong company or account
Problem: A user is redirected to a former demo, test, or unrelated company account instead of the intended production account.
Cause: The same login was associated with multiple employee records or accounts. Changing an employee email does not always change the existing login association when the login is already connected elsewhere.
Resolution:
Confirm which account and employee record should own the login.
Ask Support to remove the obsolete account association if it cannot be removed in the customer interface.
Invite the user from the correct employee record to establish the intended association.
Sign out completely, clear saved credentials if necessary, and sign in with the correct email.
Correct practice: Keep separate employee records for external consultants or administrators whose access is temporary or spans multiple companies. Do not repeatedly change one employee record’s email to represent different people or organisations.
5. “User is not assigned to the client application” or “NOT_AUTHORIZED”
Problem: SSO fails with an error such as User is not assigned to the client application or NOT_AUTHORIZED.
Cause: The user is not assigned to the ZEP application in the organisation’s identity provider, such as Okta or Microsoft Entra ID.
Resolution:
Ask the identity-provider administrator to assign the user to the ZEP application.
Confirm that the user is included in the correct group or application assignment.
Retry SSO after the assignment is active.
If the problem began after a role change, compare the affected user’s identity-provider assignment with a user who can sign in.
As a temporary business workaround, an administrator may complete the relevant approval directly in ZEP/NetSuite.
6. “Error while loading Access Token for ExtAuth (EXTERNAL_AUTH_ERROR)”
Problem: SSO fails while ZEP attempts to load the external authentication token.
Common causes: An expired client secret or an invalid or expired certificate in the customer’s identity-provider configuration.
Resolution for an expired client secret:
The customer’s identity-provider administrator creates a new client secret in the SSO application.
Share the secret value through a secure channel. Never place secrets in email or support tickets.
In ZEP, open Administration → Additional Setup → External Authentication Provider, select the provider, and enter the new secret.
Test SSO with an affected user.
Resolution for a certificate problem: The customer’s identity-provider administrator renews or corrects the certificate, then retests SSO.
Correct practice: Set calendar reminders for client-secret and certificate expiry. Keep at least two administrators with password-and-2FA access so the configuration can be repaired if SSO stops working.
7. SSO fails because the email values do not match
Problem: SSO authenticates the employee but ZEP cannot find the employee record.
Cause: The email returned by SSO, the NetSuite employee email, and the ZEP login email are different. For example, an identity provider may return a user principal name while NetSuite contains a different mailbox address.
Resolution:
Compare the email returned by SSO with the email on the NetSuite employee record.
Make the values match where possible.
If the organisation must retain different addresses for NetSuite and SSO, ask the identity-provider administrator to review the claim mapping and consult Support before changing production settings.
After synchronisation, test with the affected employee.
Do not assume that two addresses belonging to the same person are interchangeable. ZEP uses the authenticated email value to locate the employee record.
8. SSO returns to a blank page or the login screen
Problem: After SSO authentication, the browser displays a blank white page, returns to the login screen, or repeatedly redirects.
Cause: Stale browser site data or cookies can conflict with the current authentication session. In some cases, the callback from the identity provider is missing required parameters.
Resolution:
Close all ZEP tabs.
Clear cookies and site data for the ZEP domain.
Open a private browser window and retry.
If the issue affects multiple users, ask the identity-provider administrator to verify that the callback request includes both code and state.
Confirm that the configured callback URL is the exact URL provided for the ZEP environment.
A browser refresh may provide a temporary workaround, but clearing the affected site data is the more reliable user-side fix.
9. NetSuite and ZEP employee synchronization fails
Problem: An employee or user does not appear in ZEP, changes made in NetSuite are not reflected in ZEP, or an invitation cannot be created or updated.
Likely cause: An employee- or user-related integration error is blocking synchronization between NetSuite and ZEP. Common examples include missing required employee data, invalid or duplicate email addresses, an invalid employee record association, or a record that cannot be processed by the integration.
Resolution:
Open the Integration Queue in NetSuite.
Review failed or blocked tasks for the affected employee or user.
Open the integration error and read the full message, including the affected record and field.
Correct the employee or user data identified in the error. Check the email address, employee status, duplicate records, required fields, and record associations.
Retry the failed integration task or run the relevant synchronization process.
Confirm that the employee or user now appears correctly in ZEP and test access.
If the error persists, contact Support with the exact error text, employee record reference, timestamp, and steps already completed.
Important: Do not assume that a missing employee in ZEP is an invitation-delivery problem. Check employee- and user-related Integration Queue errors first, because a failed NetSuite-to-ZEP sync can prevent the account from being created or updated.
10. ZEP is slow, or search and drop-down fields keep loading
Problem: Login is slow, project or customer drop-downs spin without results, or timesheet search becomes unresponsive.
Cause: The issue was linked to slow backend search processing for certain customer data and required both backend and frontend search improvements.
Resolution: Zone deployed backend search changes and corresponding frontend updates. If the problem continues, capture the time, affected page, search term, browser, and whether other users are affected, then contact Support.
11. Admin cannot access ZEP
Problem: The only administrator cannot log in, reset the password, or receive an email.
Cause: The account may be dormant, the mailbox may not be receiving messages, or the organisation may have only one configured admin.
Resolution:
Check the mailbox, spam folders, and mail rules.
Confirm that the licence is active in NetSuite.
Contact Support to invite another employee and grant the required administrator role.
Complete registration for the new administrator.
ZEP does not automatically disable dormant accounts. A second administrator can therefore be added to restore access and provide continuity.
12. User cannot switch between companies
Problem: A user can access one company but cannot see another company after being invited.
Cause: The invitation address may be suppressed, or the user login may not be associated with the new employee record.
Resolution:
Confirm that the invitation email address is valid and can receive messages.
Check whether the address is on the email suppression list.
After the address is cleared, invite the employee from the intended company’s employee record.
Sign out and sign in again to refresh account access.
Correct practices
Maintain two or more administrators. Keep password-and-2FA access for at least some administrators even when SSO is enabled.
Keep identity data consistent. Align the NetSuite employee email, ZEP login email, and SSO email.
Invite only valid mailboxes. Create or confirm the mailbox before sending an invitation.
Protect email deliverability. Allowlist ZEP messages and do not mark them as spam.
Manage rehires carefully. Link the login to the current employee record and disable the old record’s access.
Use separate records for external users. Do not reuse one employee record for consultants, support staff, or changing email identities.
Plan SSO changes. Users registered through SSO do not automatically have a password-based login.
Track credential expiry. Set reminders for client secrets and certificates.
Assign users before rollout. Add users to the identity-provider application before enabling SSO or changing roles.
Monitor the Integration Queue. Review employee- and user-related integration errors before retrying invitations or concluding that a user is missing from ZEP.
When to contact Support
Contact Support when the quick checks do not resolve the issue, an address may be suppressed, an account is linked to the wrong employee or company, an SSO secret or certificate must be repaired, and an employee synchronization error persists.
Include the affected login email, exact error text, screenshot if available, authentication method, last known successful login, affected company or environment, Integration Queue task or error details when relevant, and the troubleshooting steps already completed. Never include passwords, client secrets, or other credentials.
Frequently asked questions
The employee may already have a registered login, the address may be suppressed, the mailbox may not exist, an employee-related integration error may be blocking synchronization, or the page may not have refreshed. Check the employee’s registration status, Integration Queue errors, and mailbox before resending.
Not if the user has never had a password. The account must be given a password-based login or recreated through the normal invitation process.
Disabling 2FA reduces account security and should not be the default solution. First check mailbox filtering, allowlist the sender, confirm delivery, and contact Support if the address is suppressed or a wider delivery incident is occurring.
Keep password-and-2FA access for designated administrators. If no administrator can access ZEP, contact Support so another employee can be invited and granted administrator access.