azureblog.co.uk
← cd ~/errors
// entra id sign-in error · mfa and registration

AADSTS90072

PassThroughUserMfaError

What it means

The external account doesn't exist in the tenant, so it can't satisfy the tenant's MFA.

How to fix it

Invite the user as a guest, or check cross-tenant trust settings for MFA.

How to investigate

  1. Open the sign-in log entry and check the Authentication details tab to see which methods were offered and which step failed.
  2. Check the user's registered methods under their Authentication methods blade.
  3. Check which Conditional Access policy or authentication strength asked for MFA.
  4. Search the sign-in logs for the request ID or correlation ID from the troubleshooting details on the error page.

Tools that help

Error names and meanings follow Microsoft's error code reference. The fixes are this site's guidance.