<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Microsoft Office 365 Error AADSTS900023 Occurs When Authenticating API Credentials In Okta

Okta Integration Network
All Engines
Okta Classic Engine
Okta Identity Engine

Overview

A misconfiguration of the Microsoft Office 365 integration in Okta causes an authentication error. Updating the Microsoft tenant to the correct value in the application settings resolves the issue. When the Microsoft Office 365 API credentials authenticate in Okta, the Microsoft login page displays the following error:

 

Sorry, but we're having trouble signing you in.
AADSTS900023: Specified tenant identifier <domainName>.onmicrosoft.com is neither a valid DNS name, nor a valid external domain.

 

Error Message

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Microsoft Office 365
  • API Credentials

Cause

A misconfiguration of the Microsoft Office 365 integration added to Okta causes the Microsoft error.

Office 365 integration in Okta 

 

Solution

How is the Microsoft Office 365 tenant identifier error resolved?

Update the Microsoft tenant value in the application settings to the correct value, and verify the administrator account configuration as detailed in the video demonstration or the written instructions.


 

      1. Navigate to Applications > Applications.
      2. Select the Microsoft Office 365 application and choose the General tab.
      3. Select Edit and update the Microsoft tenant to the correct value.
      4. Select Save.

      Ensure that the Microsoft administrator account used to enable provisioning is a non-federated account and that the account is part of the Microsoft tenant specified under the General tab of the Microsoft Office 365 integration.

      Microsoft admin account

       

      Related References

      Loading
      Okta Support - Microsoft Office 365 Error AADSTS900023 Occurs When Authenticating API Credentials In Okta