Microsoft Office 365 Tenant Change Causes AADSTS50020 Error in Okta
Last Updated:
Overview
Changing the Microsoft default domain triggers an AADSTS50020 error when attempting to log in to Microsoft Office 365 using Okta. Resolve this issue by clearing the cached credentials on the macOS or Windows machine. The following error occurs during the login attempt:
AADSTS50020: User account <usename> from identity provider <identity provider> does not exist in tenant <tenant name> and cannot access the application <application ID> (Okta Microsoft Graph Client) in that tenant. The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Single Sign-On (SSO)
- Microsoft Desktop Applications
- Service Provider (SP)-Initiated SSO
Cause
Changing the Microsoft default domain (for example, from <MyDomain.onmicrosoft.com> to <MyDomain2.onmicrosoft.com>) triggers the AADSTS50020 error due to cached credentials retaining the old tenant information.
Solution
What steps clear cached credentials on macOS?
Clear the Microsoft Office identity cache and authentication files from the macOS Keychain to resolve the login error.
- Close all Microsoft applications.
- Open Keychain and choose View, and then select Show Invisible Items.
- Search for
Microsoft Office Identities CacheandMicrosoft Office Identities Settings, and delete both entries. - Search for
com.microsoft.oneauthand delete all associated entries. - Open Microsoft Word (or any other Microsoft application) and select Sign In.
Windows requires clearing the cached credentials.
Review the documentation for clearing cached credentials in Windows to resolve the login error.
- Please review How to clear cached credentials in Windows.
