Trying to administer B2C tenant results in "User authorization failed. You must have access to "

Basim Kadhim 26 Reputation points
2020-06-08T22:05:12.067+00:00

I originally created the tenant, but now it does not show up as a tenant for me to switch to, though it does show up under the subscription that it is assigned to in my primary tenant. The co-administrator of mine that does have access to the tenant has confirmed that I'm listed as a Global Administrator, but I still can't seem to access the B2C tenant to administer users. Why would this be?

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,634 questions
0 comments No comments
{count} votes

Accepted answer
  1. AmanpreetSingh-MSFT 56,301 Reputation points
    2020-06-12T17:32:43.847+00:00

    @KellyH-3558 Thank you for your time on call today.

    As discusses, the problematic user accounts were added as consumer accounts by signing up using federated Azure Active Directory. These accounts are not supposed to be used for Administration purpose. The signed-up accounts should be used only to provide access to the application federated with B2C directory.

    For administration purpose, user accounts should be added as members directly using Azure AD > New User option or by adding them as guests using Azure AD > New Guest User option.

    Issue resolved by removing the signed-up user accounts and adding them as guest accounts to the B2C directory.


    Please do not forget to "Accept the answer" wherever the information provided helps you. This will help others in the community as well.


1 additional answer

Sort by: Most helpful
  1. AmanpreetSingh-MSFT 56,301 Reputation points
    2020-06-11T09:30:36.317+00:00

    Hello @BasimKadhim-1280

    Could you please confirm if you are able to access B2C directory using below method:

    Alternatively, you can try signing-in to B2C directory via powershell connect-azuread -TenantId yourB2Ctenant.onicrosoft.com

    This will confirm if this is a UI issue or permissions issue.

    Also make sure you are looking under all directories when you try to switch directory as highlighted below:

    9739-untitled.png


    Please do not forget to "Accept the answer" wherever the information provided helps you. This will help others in the community as well.