Federated user getting AADSTS51004 on SAML login attempt

Jason Bradford 6 Reputation points
2020-05-28T23:37:05.05+00:00

I have federated our O365 AAD domain with our GSuite domain as the SAML IdP. Access is granted via membership to a specific gsuite group. This generally works after having to set UPN = ImmutableID.

I have a user who, after migrating to a new computer, tried to authenticate their applications or log into the Office portal and receives "Message: AADSTS51004: The user account xxxxxxxxxxxxxxxxxxxx does not exist in the yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy directory. To sign into this application, the account must be added to the directory.

Nothing has been changed WRT the user's user object in either system. When I Get-AzureADUser, this user appears in the output as expected and everything looks correct. In the admin portal they also show up properly and are licensed just the same. I have tried having them clear cache and cookies with no change in results. I had another user several months back who ran into the same or very similar issue when we set them up on their repaired machine. This seems to be the commonality (changing the user machine) with both instances. The first one I tried several things down to deleting the O365 user hoping to re-propagate them into Azure but then needed to have Google support make some database edit before they would re-propagate so I don't really want to go that route again.

Anybody have an explanation and/or fix for this?

Thanks
--Jason

Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,666 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Marilee Turscak-MSFT 34,311 Reputation points Microsoft Employee
    2020-08-26T00:29:43.117+00:00

    Here is how you transfer domains between subscriptions: https://learn.microsoft.com/en-us/microsoft-365/admin/get-help-with-domains/transfer-data-manually?view=o365-worldwide

    If you want to remove a custom domain from a tenant and add it to another tenant, you can follow the steps from these articles:

    1. Remove a domain from Office 365
    2. Add your users and domain to Office 365

    Let me know if this is what you are looking for!

    0 comments No comments

  2. Cengiz Kuskaya 1 Reputation point
    2021-02-07T14:56:28.667+00:00

    Hi Jason,

    I have experienced the same problem like you too and found the solution after severaal hours of investigation. You can take a look at the following article if you still experiencing the probem.

    How to troubleshoot “AADSTS51004: The user account XXX does not exist in the XXX directory. To sign into this application, the account must be added to the directory.” Error Message

    Hope it helps !

    Regards,
    Cengiz

    0 comments No comments