They are probably already doing this - but when the user logs into Field Maps, are the logging in the exact same way as they do to ArcGIS Online or if they access the server?
For example - we have SAML/Google hosted logins. If users log into Field Maps with the text boxes instead of using the organization log in, Field Maps tends to not function correctly for the user! So in this scenario, if the user is not logged into Field Maps with the same credentials as they would for Online, that could be the problem.
Aside from Field Maps - is the user able to access the service in a browser window? You may have already tried this, but I would have the user try to login/access the map service in a browser window (probably Chrome) first to see is you have the same error! If they can't login through the browser, it will for sure not work in Field Maps. At that point, it might be a server/domain issue.
Good luck with your projects!
We're currently experiencing this same issue within our organization. Did you find out what was causing the problem or a fix for it?
We're running into a similar issue. We use a stand-alone ArcGIS server to power our Field Maps with data from an SQL server. Our users in one department intermittently won't be able to log-in. They can try and fail, pass me the device, and my credentials will work. We've checked AD and web service permissions. There is no reason they should not be able to get in. What's even more curious is that some days it works for them.