I was testing Cloudflare Zero Trust Access integration with auth0 and I used the “remove” feature on a user in the users’ list, now when I try to login into a secured application with that user email it tells me “That account does not have access”.
I was able to re-authorize a removed user by adding them to an “include” or “require” login policy in my application, revoking all active tokens for that application, clearing browser cache, then logging in with that account. Not sure if that’s a fluke, but it’s worth a shot in your case.