Credentials don't work for IRM-protected content


Office 365 ProPlus is being renamed to Microsoft 365 Apps for enterprise. For more information about this change, read this blog post.


When you try to open an Information Rights Management (IRM)-protected document, workbook, email message, or other item, you discover that you don't have access to the item even though you correctly signed in to Microsoft Office. Additionally, you're prompted to sign in, but you still can't access the content when you should be able to access to it.

This symptom is usually that you are prompted to sign in but your credentials don't work.


This behavior occurs when the following conditions are true:

  • Your environment is configured for cross-domain authentication.
  • The domain where the content is created is configured to have Conditional Access requirements.
  • The authentication fails.

For example, ** protects content and sends it to **. To access the protected content, ** has to authenticate to to obtain the key to decrypt the content. If has Conditional Access requirements, this authentication may fail.

Most Conditional Access challenges require that the user is provisioned in the resource tenant ( If the guest user (**) is explicitly invited and the invitation is redeemed, ** is provisioned in the resource tenant If the user is a pass-through user, the Conditional Access validation code servicing doesn't have a way to satisfy the challenges, and so the request fails. This is expected and secure behavior. For many cases, this behavior causes the Office client code to prompt for sign-in so that the user can supply credentials to open the file because authentication failed.


For more information about Conditional Access policies, see the following blog:

Conditional Access policies for Azure Information Protection