Getting "Selected user account does not exist in tenant 'Microsoft Services' and cannot access the application" error.

B B 221 Reputation points
2021-12-31T20:29:52.23+00:00

Good afternoon:

Any time I try to go to security.microsoft.com or compliance.microsoft.com and log in, I'm greeted with a "Selected user account does not exist in tenant 'Microsoft Services' and cannot access the application" error. The same account credentials log me into portal.azure.com and office.com just fine.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,498 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,434 questions
{count} votes

16 answers

Sort by: Most helpful
  1. Brian Brown 0 Reputation points
    2024-08-21T15:01:09.3533333+00:00

    I had an excellent MSFT support technician help me out with this problem. The advice we've all heard - that you, as a Global Admin, must create an external user and make them a Global Admin - is not correct. You must instead, as a "Global Admin", create an internal user and make them a Global Admin. That Global Admin user should have the access that you, as the sole owner of your own Azure subscription, and supposed "Global Admin", do not have. Note my very selective use of quotes.

    I asked the technician why this Byzantine circus was necessary, and he explained that, for most purposes, the owner is a "User" and not a Guest. However, in some dark, weird, way, this is not entirely correct. Owners are actually Guests with most "User" privileges. Yes, if you look up your user account, it plainly says "User". And I'm telling you that's not entirely true.

    So now the workaround makes sense. We make ourselves "Global Admin", create a user as a real, bona fide Global Admin, and use them to log into these websites. Call it "security by obscurity" if you're feeling cynical.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.