azureblog.co.uk
← cd ~/errors
// entra id sign-in error · accounts, passwords and sessions

AADSTS50020

UserUnauthorized

What it means

The user's account isn't from this tenant and can't access the app.

How to fix it

Invite the user as a guest, or point the app at the right tenant (or the common or organizations endpoint).

How to investigate

  1. Confirm which account the user actually signed in with. A personal account or the wrong tenant causes many of these.
  2. Check the user object: enabled, licensed, in the right tenant, and with no recent password change or reset.
  3. Look at the sign-in logs over a few days for a pattern, such as repeated failures from one IP address.
  4. Search the sign-in logs for the request ID or correlation ID from the troubleshooting details on the error page.

Tools that help

Error names and meanings follow Microsoft's error code reference. The fixes are this site's guidance.