Deleted my Azure Active Directory profile. How to restore?

Eugene G 1 Reputation point
2022-08-18T12:09:05.893+00:00

Hi,

I have accidentally deleted my active admin directory profile in https://account.activedirectory.windowsazure.com.

Error message below:

Details: The logged in user is not authorized to fetch tokens for extension 'Microsoft_AAD_IAM' because the user account is not a member of tenant '-----------------------------------'.

Error details: AADSTS50020: User account '{EmailHidden}' from identity provider 'live.com' does not exist in tenant 'Microsoft Services' and cannot access the application '--------------------------'(Azure Portal) in that tenant. The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account.

Pls help, thanks!

Azure Active Directory
Azure Active Directory
An Azure enterprise identity service that provides single sign-on and multi-factor authentication.
13,486 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Carlos Solís Salazar 10,971 Reputation points
    2022-08-18T13:58:51.403+00:00

    Hi @Eugene G

    Thank you for asking this question on the **Microsoft Q&A Platform. **

    An administrator has to restore the user from the folder "Deleted Users" in https://admin.microsoft.com

    Hope this helps,
    Carlos Solís Salazar

    ----------

    Accept Answer and Upvote, if any of the above helped, this thread can help others in the community looking for remediation for similar issues.
    NOTE: To answer you as quickly as possible, please mention me in your reply.


    1 person found this answer helpful.

  2. JamesTran-MSFT 27,506 Reputation points Microsoft Employee
    2022-08-22T20:53:06.06+00:00

    @Eugene G
    Thank you for following up on this and I apologize for the delayed response!

    Error Message:
    AADSTS50020: User account '{EmailHidden}' from identity provider 'live.com' does not exist in tenant 'Microsoft Services' and cannot access the application...The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account.

    Because you've accidentally deleted the only user in your tenant and are unable to create a support request, you'll have to reach out to our Azure Data Protection team for further assistance - (866-807-5850) in recovering your user and Azure AD tenant.

    For future reference, I'd also recommend creating and managing an emergency access account in Azure AD, this will help prevent being accidentally locked out of your Azure Active Directory (Azure AD) organization because you can't sign in.

    Additional Link:
    Global Customer Service phone numbers

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.