Can't go to Azure Active Directory in a newly created account.

Tech Stafflink 1 Reputation point
2022-08-15T01:41:29.233+00:00

I'm having viewing the Azure Active directory blade in my newly created account.

The error I'm getting is below:

The portal is having issues getting an authentication token. The experience rendered may be degraded.

Additional information from the call to get a token:
Extension: Microsoft_Azure_Support
Resource: self
Details: The logged in user is not authorized to fetch tokens for extension 'Microsoft_Azure_Support' because the user account is not a member of tenant 'xxxx-xxxx-xxxx-xxxx-xxxx'. Error details: AADSTS50020: User account '{EmailHidden}' from identity provider 'live.com' does not exist in tenant 'Microsoft Services' and cannot access the application 'xxxx-xxxx-xxxx-xxxx-xxxx'(Azure Portal) in that tenant. The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account.
Trace ID: xxxx-xxxx-xxxx-xxxx-xxxx
Correlation ID: xxxx-xxxx-xxxx-xxxx-xxxx
Timestamp: 2022-08-15 01:38:13Z

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

2 answers

Sort by: Most helpful
  1. David Broggy 6,376 Reputation points MVP Volunteer Moderator
    2022-08-15T02:57:06.317+00:00

    Hi TechStaff,
    Have you tried logging in with a PrivateBrowser/Incognito?
    If this is a non-Azure domain user account, did you add them as a guest, or does the new user match your azure domain (eg. bob@Company portal .com - contoso.com being your domain).

    0 comments No comments

  2. risolis 8,741 Reputation points
    2022-08-15T03:33:03.773+00:00

    Hello @Tech Stafflink

    Thank you for your post.

    On this case scenario, as @David Broggy was saying, you need to either use the @onmicrosoft.com on the user that you created or was given from the admin group.

    If you want to use a customer email address like outlook.com or hotmail.com or any other, this has to be added as a external user... Then you will get an email invitation on your email address that was used.

    This will take you directly to the correct Tenant/Subscription for you to log in.

    Please ensure that if any azure role was given that it was approved from the PIM blade(Privileged Identity Management)

    I hope this can be useful to get this going : )

    Looking forward to your feedback,

    Cheers,

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.