Entra ID Self Service Sign-up: How to debug why it doesn't work for a particular tenant?

Jason Lee 181 Reputation points
2024-08-27T22:13:40.49+00:00

Hi,

I setup Self Service Sign up as per this article.

https://learn.microsoft.com/en-gb/entra/external-id/self-service-sign-up-overview?WT.mc_id=Portal-Microsoft_AAD_IAM

Sign Up works great with another Entra ID tenant I created and with Google. However, when I try to sign up with an account from my company's Entra ID tenant, I get redirected back to the sign in page with the error message "This account does not exist in this organization" at the end of the sign up flow after authenticating into my company's tenant. What could be wrong and how can I prove the root cause of the problem?

User's image

I looked at all the Entra ID sign in, audit, and provisioning logs but there's no entries directly correlated to the time of the failed sign in attempt. I suspect that my company's tenant has restrictions on the External Identities outbound access settings but I can't verify that since I don't have admin access to that tenant. Is there a way to determine if that is why I get that error?

Thanks in advance!

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,927 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,198 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Akhilesh Vallamkonda 10,325 Reputation points Microsoft Vendor
    2024-09-03T00:41:08.5+00:00

    Hi @Jason Lee

    Thank you for reaching us!

    I understand that you have setup Self Service Sign up when you are using the flow it is not allowing you with Entra ID account.

    It might be cause of this error is using the incorrect sign-in URL. For example, if you use https://login.Microsoftonline.com/<YourTenantNameOrID> URL, the authentication is expected to be run on your tenant only. That’s why users in other organizations cannot access the application. Use the corresponding sign-in URL for a specific type of application.
    The other side could you please check capabilities as per below document.
    https://learn.microsoft.com/en-us/entra/identity/users/directory-self-service-signup#how-can-i-control-these-capabilities

    Hope this helps. Do let us know if you any further queries by responding in the comments section.

    Thanks,

    Akhilesh.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.