AADSTS50105 🔷 Azure

AADSTS50105: Your administrator has configured the application to block users unless they are specifically granted access

The enterprise app requires assignment (“Assignment required? Yes”) and the user isn’t assigned to it, directly or via a group.

Seen on: Azure

Meaning

Common with SSO apps (SAML/OIDC). Nested groups don’t count for assignment, and dynamic group membership can take time to update.

Common causes

  • User not assigned to the enterprise application
  • Assigned via a nested group (not supported)
  • Group membership not yet updated

⚡ Quick fix

  1. Assign the user or a direct group in Enterprise applications → Users and groups
  2. Or set Assignment required to No if open access is intended

Detailed fix by platform

Azure CLI

  1. az ad sp show --id <app-id> --query appRoleAssignmentRequired

How to diagnose

  1. Assignment — User/group listed?
  2. Groups — Direct membership?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.