AADSTS50020: User account from identity provider does not exist in tenant and cannot access the application
The signed-in user belongs to another tenant (or is a personal Microsoft account) and isn’t a guest in the app’s tenant.
Seen on:
Azure
Meaning
Single-tenant apps only accept their own users. Signing in with a personal/other-org account, or calling the wrong authority (/common vs /tenant-id), triggers 50020.
Common causes
- User not invited as a guest
- App registered as single-tenant but used by other orgs
- Browser signed in with a different account
- Wrong authority URL
⚡ Quick fix
- Invite the user as a B2B guest
- Make the app multi-tenant if intended
- Sign out/use a private window and pick the right account
Detailed fix by platform
Azure CLI
az ad user list --filter "mail eq 'user@partner.com'" --query "[].userType"
How to diagnose
- Account — Which tenant does it belong to?
- App — Supported account types
- Authority — /common, /organizations or tenant ID?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Azure
- AADSTS50076 Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
- AuthorizationPermissionMismatch Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission
- App Service Application Error Azure App Service: ":( Application Error" / container didn’t respond to HTTP pings
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026