I have Entra federated with Okta. One of my users is getting this error: AADSTS50105: The signed in user is blocked because they are not a direct member of a group with access. My problem is that they are a member of a group with access and assigned app.

Mary 20 Reputation points
2025-02-28T03:11:59.84+00:00

Hi, One of my users is getting this error when trying to log in to the other IDP using Entra federation:

Message: AADSTS50105: Your administrator has configured the application to block users unless they are specifically granted ('assigned') access to the application. The signed in user is blocked because they are not a direct member of a group with access, nor had access directly assigned by an administrator. Please contact your administrator to assign access to this application.

The issue is that she is a group member and has the app assigned to her. None of my other users in this group are having this error.

I've checked everything I can think of unless there is a policy that may be blocking it for her. Could that be? Has anyone else run into this?

I'm new to this. Plz help.

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
3,073 questions
0 comments No comments
{count} votes

Accepted answer
  1. Chaithra E 790 Reputation points Microsoft External Staff
    2025-03-03T13:34:01.58+00:00

    Hello @Mary,

    Thank you for reaching out on Microsoft Q&A.

    Based on your description, it looks like a user is encountering the error AADSTS50105: The signed-in user is blocked because they are not a direct member of a group with access. However, you mentioned that the user is already a member of the assigned group and has access to the application.

    This error typically occurs when signing in to an application configured to use Microsoft Entra ID for identity management via SAML-based Single Sign-On.
    To resolve this, please ensure that the user has been correctly assigned to the application by following the steps outlined in https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/add-application-portal-assign-users.

    Since the AADSTS50105 error is coming from Entra ID, it indicates that the authentication request is being blocked after Okta has verified the user, most likely due to Conditional Access policies.
    A Conditional Access policy might be restricting access based on the user’s group membership, location, or device state. I recommend checking Microsoft Entra ID to review any policies that might be affecting this user.
    You can also refer to this below link that helps you to identify which Conditional Access policy is causing the issue.
    https://learn.microsoft.com/en-us/entra/identity/conditional-access/troubleshoot-conditional-access

    Let me know if this helps or if you need further clarification.

    I hope this information is helpful. Please feel free to reach out if you have any further questions. If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Thanks,
    Chaithra.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.