使用單一登入SSO 將網域設定到GOOGLE登入頁面但是,從GOOGLE登入有些會失敗

芳鄰 網路 0 Reputation points
2024-04-30T12:25:33.6266667+00:00

使用單一登入SSO 將網域設定到GOOGLE登入頁面但是,因為一開始還未使帳號用同步時,就已經建立帳號,之後那些帳號從GOOGLE登入有些會失敗會出現以下畫面,造成全域管理員帳號無法進入

AADSTS51004: The user account user@domain.com does not exist in the 8ddde8ec-9e1b-4f56-8952-11894fefb6b0 directory. To sign into this application, the account must be added to the directory.

Request Id: 4f09b5e7-1d01-47b8-9f19-95589e1b5701

Correlation Id: 3effc13b-4102-4fbf-9be1-e2f92b8b661b

Timestamp: 2024-04-30T05:56:24Z

Message: AADSTS51004: The user account user@domain.com does not exist in the 8ddde8ec-9e1b-4f56-8952-11894fefb6b0 directory. To sign into this application, the account must be added to the directory.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,762 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Sandeep G-MSFT 14,826 Reputation points Microsoft Employee
    2024-05-02T09:46:47.58+00:00

    @芳鄰 網路

    Thank you for posting this in Microsoft Q&A.

    Error code: AADSTS51004 is states the user account doesn’t exist in the directory. An application likely chose the wrong tenant to sign into, and the currently logged in user was prevented from doing so since they did not exist in your tenant. If this user should be able to log in, add them as a guest. For further information, please visit add B2B users. Make sure that the user account email is added to the directory before you can sign into the application.

    Reason behind the error you saw is, that when you created these users via google, their email became their immutable, and it worked fine, however if you create users directly in Office 365 /Ad sync, then you would first need to ensure immutable = user’s email address. I hope this information helps! If you have any further questions, please feel free to ask.

    For more information, please refer https://learn.microsoft.com/en-us/answers/questions/465354/erro-aadsts51004-ao-configurar-integra-o-do-gsuite

    https://learn.microsoft.com/en-us/answers/questions/1306272/configured-google-as-idp-via-federation-now-cant-l

    https://learn.microsoft.com/en-us/education/windows/configure-aad-google-trust

    Let me know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.