Microsoft Office 365 Error AADSTS900023 Occurs When Authenticating API Credentials In Okta
Last Updated:
Overview
A misconfiguration of the Microsoft Office 365 integration in Okta causes an authentication error. Updating the Microsoft tenant to the correct value in the application settings resolves the issue. When the Microsoft Office 365 API credentials authenticate in Okta, the Microsoft login page displays the following error:
Sorry, but we're having trouble signing you in.
AADSTS900023: Specified tenant identifier <domainName>.onmicrosoft.com is neither a valid DNS name, nor a valid external domain.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Microsoft Office 365
- API Credentials
Cause
A misconfiguration of the Microsoft Office 365 integration added to Okta causes the Microsoft error.
Solution
How is the Microsoft Office 365 tenant identifier error resolved?
Update the Microsoft tenant value in the application settings to the correct value, and verify the administrator account configuration as detailed in the video demonstration or the written instructions.
- Navigate to Applications > Applications.
- Select the Microsoft Office 365 application and choose the General tab.
- Select Edit and update the Microsoft tenant to the correct value.
- Select Save.
Ensure that the Microsoft administrator account used to enable provisioning is a non-federated account and that the account is part of the Microsoft tenant specified under the General tab of the Microsoft Office 365 integration.
