AADSTS50105: Your administrator has configured the application to block users unless they are specifically granted access
The enterprise app requires assignment (“Assignment required? Yes”) and the user isn’t assigned to it, directly or via a group.
Seen on:
Azure
Meaning
Common with SSO apps (SAML/OIDC). Nested groups don’t count for assignment, and dynamic group membership can take time to update.
Common causes
- User not assigned to the enterprise application
- Assigned via a nested group (not supported)
- Group membership not yet updated
⚡ Quick fix
- Assign the user or a direct group in Enterprise applications → Users and groups
- Or set Assignment required to No if open access is intended
Detailed fix by platform
Azure CLI
az ad sp show --id <app-id> --query appRoleAssignmentRequired
How to diagnose
- Assignment — User/group listed?
- Groups — Direct membership?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Azure
- AADSTS50076 Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
- AuthorizationPermissionMismatch Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission
- AADSTS700016 Azure AD (Entra ID): AADSTS700016 Application not found in the directory
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026