AADSTS50020 🔷 Azure

AADSTS50020: User account from identity provider does not exist in tenant and cannot access the application

The signed-in user belongs to another tenant (or is a personal Microsoft account) and isn’t a guest in the app’s tenant.

Seen on: Azure

Meaning

Single-tenant apps only accept their own users. Signing in with a personal/other-org account, or calling the wrong authority (/common vs /tenant-id), triggers 50020.

Common causes

  • User not invited as a guest
  • App registered as single-tenant but used by other orgs
  • Browser signed in with a different account
  • Wrong authority URL

⚡ Quick fix

  1. Invite the user as a B2B guest
  2. Make the app multi-tenant if intended
  3. Sign out/use a private window and pick the right account

Detailed fix by platform

Azure CLI

  1. az ad user list --filter "mail eq 'user@partner.com'" --query "[].userType"

How to diagnose

  1. Account — Which tenant does it belong to?
  2. App — Supported account types
  3. Authority — /common, /organizations or tenant ID?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.