Microsoft Office 365 Error AADSTS900023 Occurs When Authenticating API Credentials in Okta
Last Updated:
Overview
When authenticating Microsoft Office 365 API credentials in Okta, an authentication error occurs due to a misconfiguration in the integration. Resolve this issue by updating the Microsoft tenant to the correct value in the application settings. The Microsoft login page displays the following AADSTS900023 error, indicating that the specified tenant identifier is invalid.
Sorry, but we're having trouble signing you in.
AADSTS900023: Specified tenant identifier <domainName>.onmicrosoft.com is neither a valid DNS name, nor a valid external domain.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Microsoft Office 365
- API Credentials
Cause
A misconfiguration of the Microsoft tenant domain in the Microsoft Office 365 integration settings in Okta causes the Microsoft error.
Solution
How is the Microsoft Office 365 tenant identifier error resolved?
Navigate to the Microsoft Office 365 application settings in the Okta Admin Console and update the Microsoft tenant to the correct value as detailed in either the video demonstration or the written instructions.
- Navigate to Applications > Applications.
- Select the Microsoft Office 365 application and choose the General tab.
- Select Edit and update the Microsoft tenant to the correct value.
- Select Save.
Verify that the Microsoft administrator account used to enable provisioning is a non-federated account and is part of the Microsoft tenant specified under the General tab of the Microsoft Office 365 integration.
