Thank you for posting this in Microsoft Q&A.
As I understand when user tries to login to application configured in your tenant, they are getting error AADSTS500014
This can be caused when the underlying Service Principal used as the app identity of the cited resource might be disabled.
You can have an AAD/Global Admin run the following from an AzureAd PowerShell window.
- Open Windows PowerShell as administrator.
- Run command “Install-Module azuread”.
- Once installed you can run command “Connect-AzureAD” and enter user credentials once it asks for.
- Now run comment "Set-AzureADServicePrincipal -ObjectId <Service Principal Object Id> -AccountEnabled $true".
Apart from this you can also check if this application is enabled for user sign-in.
Let me know if you have any further questions.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.