External guest invited users getting Sign-in error code 50133

Raja Thammaneni 0 Reputation points
2024-02-13T04:23:35.89+00:00

External guest user accounts were created by invitation email. The user accounts with an identity provider Email one-time code (Identity: mail) cannot sign in due to sign-in error code 50133. Failure reason The session is not valid due to password expiration or recent password changes. Additional Details Expected - auth codes, refresh tokens, and sessions expire over time or are revoked by the user or an admin. The app will request a new login from the user. When we try to revoke the sessions and re-invite, the accept URL says, "We can not find the user account." This happens in most external guest user accounts where the identity is "mail." Conditional access policies: success and authentication details: Previously satisfied. We appreciate the help. Thank you, Raja

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. James Hamil 27,221 Reputation points Microsoft Employee Moderator
    2024-02-14T21:11:58.1066667+00:00

    Hi @Raja Thammaneni , this error can occur when the authentication codes, refresh tokens, and sessions expire over time or are revoked by the user or an admin.

    To resolve this issue, you can try resetting the user's password in your on-premises Active Directory. You can also check if your Active Directory is reachable from the Authentication Agent. If the problem is consistently reproducible across multiple users, you may need to check your Active Directory configuration.

    If you have already tried revoking the sessions and re-inviting the user, but the accept URL says "We can not find the user account," it is possible that the user account has been deleted or is no longer valid. In this case, you may need to create a new invitation for the user.

    Please let me know if you have any questions and I can help you further. If this answer helps you please mark "Accept Answer" so other users can reference it.

    Thank you,

    James


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.