Okta Office 365 API Error AADSTS50020 "The account needs to be added as an external user in the tenant first"
Last Updated:
Overview
The Office 365 Graph API authentication flow fails in Okta when the Microsoft admin account used for authentication does not belong to the configured Microsoft domain. Authenticate the API using a Microsoft account that belongs to the Microsoft domain defined in the integration settings.
The Office 365 Graph API authentication flow fails, and Okta displays the following error message in the dashboard, indicating the user account does not exist in the tenant.
AADSTS50020: User account <usename> from identity provider <identity provider> does not exist in tenant <tenant name> and cannot access the application <application ID> (Okta Microsoft Graph Client) in tenant. The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Office 365
- Provisioning
- Graph Client
Cause
The Microsoft admin account used to authenticate the API does not belong to the Microsoft domain configured in the General tab of the Office 365 Okta integration.
The following image displays the configured Microsoft domain in the general settings of the Office 365 integration.
Solution
What resolves the Office 365 API authentication error?
Resolve the authentication error by navigating to the general settings of the Office 365 integration and authenticating the API with a valid Microsoft account as detailed in either the video demonstration or the written instructions.
- Open the Office 365 Okta integration.
- Navigate to the General tab.
- Authenticate the API using a Microsoft account that belongs to the Microsoft domain defined in the settings.
