Share via

Request Id: PII

my-vpa Vanessa Mazzola 0 Reputation points
2026-05-20T11:33:25.07+00:00

Request Id: PII

Correlation Id: PII

Timestamp: 2026-05-20T11:29:20Z

Message: AADSTS50020: User account 'PII' from identity provider 'live.com' does not exist in tenant 'Microsoft Services' and cannot access the application '0ec893e0-5785-4de6-99da-4ed124e5296c'(Microsoft 365 Copilot) in that tenant. The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. AI answer

    2026-05-20T11:33:45.69+00:00

    The error indicates that the account ******@my-vpa.com, which is backed by the live.com identity provider (a personal Microsoft account), does not exist as a user in the Microsoft Services tenant and therefore cannot access the Microsoft 365 Copilot application in that tenant.

    Based on the provided context, the relevant causes and actions are:

    1. The account is not in the tenant that owns the app
      • The error text explicitly states that the user account from identity provider live.com does not exist in tenant Microsoft Services and cannot access the application.
      • To use this tenant’s application, the account must be added as an external (guest) user in that tenant.
      • If there is an administrator for the Microsoft Services tenant, that administrator must invite this live.com account as a guest user following the steps in “Quickstart: Add guest users to your directory in the Azure portal”.
    2. Possible wrong tenant/session
      • The error can also occur if signed in to the wrong tenant or with the wrong account session.
      • Sign out from all active sessions and then sign in again, preferably using a different browser or an in-private/incognito session, and ensure the correct Microsoft Entra ID tenant and account are used.
    3. Personal account vs. tenant account
      • The message shows identity provider 'live.com', which is a personal Microsoft account. If Microsoft 365 Copilot in this scenario is intended only for organizational (work/school) accounts in a specific tenant, a personal live.com account will not work unless explicitly added as a guest.
    4. Universal Print–style guidance (same error pattern)
      • Similar guidance for Universal Print with the same error code states that the credentials must be an account in the Microsoft Entra ID tenant that is using the service. By analogy, to use Microsoft 365 Copilot in this tenant, sign in with an account that belongs to that tenant (or a guest account that has been properly invited).

    Summary of what must happen:

    • Either:
      • Use a Microsoft Entra ID account that actually exists in the Microsoft Services tenant and has access to Microsoft 365 Copilot.
    • Or:
      • Have the tenant administrator invite ******@my-vpa.com as a guest user to that tenant, redeem the invitation, then sign out and sign back in (preferably via a private browser session) with that invited account.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.