Azure Mutliteant Application Other Organization Not able to login main tenant application Throw Token failed resulted in a 400 Bad Request response "error":"invalid_request","error_description":"AADSTS50146

Alok Saxena 1 Reputation point
2021-12-01T07:00:37.007+00:00

Hi

ORG-A who developed the SAAS Application in Multitenant with SSO, which is used by ORG-A and ORG-B

I am unable to figure out why token failed when users from other ORG B try to login from either their office network or outside, it throws a bad request for a token, BUT first (Main) ORG A can successfully login from their office or outside the network.

ORG A-Main who developed the application

App Registration: SPAApp [SPA Application [Angular] & Android]

153957-spaapp-auth.jpg

153985-spaapp-permission.jpg

App Registration: WebApiApp

153878-apiapp-auth.jpg
153958-apiapp-permission.jpg
153959-apiapp-expose-an-api.jpg

External Organization ORG-B

The Above APP Regs is a service principal in Other Organization Azure AD Enterprise Application.
Attached the screen shot,

'login.microsoftonline.com/common/oauth2/v2.0/token` resulted in a 400 Bad Request response
{error: "invalid_request",…}
correlation_id: "a5c16c75-6144-4589-b8b8-a387e58e66ca"
error: "invalid_request"
error_codes: [50146]
error_description: "AADSTS50146: This application is required to be configured with an application-specific signing key. It is either not configured with one, or the key has expired or is not yet valid.\r\nTrace ID: 8bddc548-394c-4a11-b294-da51c209c801\r\nCorrelation ID: a5c16c75-6144-4589-b8b8-a387e58e66ca\r\nTimestamp: 2021-12-01 05:55:26Z"
error_uri: "https://login.microsoftonline.com/error?code=50146"
timestamp: "2021-12-01 05:55:26Z"
trace_id: "8bddc548-394c-4a11-b294-da51c209c801"

153945-other-org-login-issue.jpg
153926-other-org-login-issue-payload.jpg
153946-other-org-login-issue.jpg

----------

Hello Experts

Few names appear in my mind, @sikumars-msft , @Vinod Survase , @AmanpreetSingh-MSFT @Dave Patrick , @Andy David - MVP , @Andreas Baumgarten , @António Sérgio Azevedo , It will be great if any one who are not above list too, can shed some light on it.

Thanks In - Advance

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,468 questions
0 comments No comments
{count} votes