Skip to content

Commit 585973c

Browse files
author
Simonx Xu
authored
Merge pull request #8205 from AmandaAZ/Branch-CI3195
AB#3195: Private version of PR#1739
2 parents 9ce75e4 + e8a6e87 commit 585973c

File tree

2 files changed

+49
-0
lines changed

2 files changed

+49
-0
lines changed
Lines changed: 47 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
1+
---
2+
title: Error AADSTS700003 - Device Object Was Not Found in the Tenant Directory
3+
description: Provides a solution to an issue where you experience the AADSTS700003 error when you try to sign in to an Azure application that can be used with Microsoft Entra ID.
4+
ms.service: entra-id
5+
ms.date: 02/24/2025
6+
ms.reviewer: jutakata, willfid, bachoang, joaos, modawud, v-weizhu
7+
ms.custom: sap:Issues Signing In to Applications
8+
---
9+
10+
# Error AADSTS700003 - Device object was not found in the tenant '\<TenantName\>' directory
11+
12+
This article discusses how to resolve the "AADSTS700003" error that occurs when you try to sign in to an application that's integrated into Microsoft Entra ID.
13+
14+
## Symptoms
15+
16+
When you try to sign in to an application that's integrated into Microsoft Entra ID, you receive an "AADSTS700003" error with one of the following error messages:
17+
18+
- > Device object was not found in the tenant '\<TenantName\>' directory.
19+
- > Your organization has deleted this device.
20+
21+
## Cause
22+
23+
This issue occurs because the device object is deleted on your home tenant. When a device is deleted, the "Delete device" activity type is recorded in the [Microsoft Entra audit log](/entra/identity/monitoring-health/concept-audit-logs). In Microsoft Entra ID, there are three ways to register or join user devices:
24+
25+
- Microsoft Entra registered
26+
- Microsoft Entra joined
27+
- Microsoft Entra hybrid joined
28+
29+
Device registration or join creates a [device identity](/entra/identity/devices/overview). This device identity is used in scenarios such as [device-based Conditional Access policies](/entra/identity/conditional-access/concept-conditional-access-grant) and [Mobile Device Management with Microsoft Intune](/mem/endpoint-manager-overview). When you receive the AADSTS700003 error, the device object isn't found in the tenant.
30+
31+
## Solution
32+
33+
Engage the home tenant administrators to determine when and why your device object is deleted. Then, take the corresponding action depending on the device registration/join type, as shown in the following table:
34+
35+
| Device join type | Action |
36+
|--|--|
37+
| Microsoft Entra registered | For Windows 10/11 Microsoft Entra registered devices, go to **Settings** > **Accounts** > **Access Work or School**. Select your work or school account on the screen. Select **Disconnect** to disconnect the device. Then, register the device to Microsoft Entra ID again.<br/><br/>For iOS and Android, you can use the Microsoft Authenticator application and select **Settings** > **Device Registration** > **Unregister device**. Then, register the device to Microsoft Entra ID again.<br/><br/>For macOS, you can use the Microsoft Intune Company Portal application to unenroll the device from management and remove any registration. Then, register the device to Microsoft Entra ID again.<br/><br/> For more information, see [Microsoft Entra register FAQ](/entra/identity/devices/faq#how-do-i-remove-a-microsoft-entra-registered-state-for-a-device-locally).|
38+
| Microsoft Entra joined | Open a PowerShell console with the administrative right on the Windows device, and run the `dsregcmd /forcerecovery` command. Select **Sign in** to sign in with your Microsoft Entra ID account. |
39+
| Microsoft Entra hybrid joined | Open a PowerShell console with the administrative right on the Windows device, and run the `dsregcmd /leave` command. Then, reboot the device and sign in to the device with your domain credential. |
40+
41+
## More information
42+
43+
For a full list of authentication and authorization error codes, see [Microsoft Entra authentication and authorization error codes](/azure/active-directory/develop/reference-error-codes).
44+
45+
To investigate individual errors, go to [https://login.microsoftonline.com/error](https://login.microsoftonline.com/error).
46+
47+
[!INCLUDE [Azure Help Support](../../../includes/azure-help-support.md)]

support/entra/entra-id/toc.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -98,6 +98,8 @@
9898
href: app-integration/error-code-AADSTS75005-not-a-valid-saml-request.md
9999
- name: Error AADSTS750054 - SAML request or response not present
100100
href: app-integration/error-code-AADSTS750054-saml-request-not-present.md
101+
- name: Error AADSTS700003 - Device object was not found in the tenant directory
102+
href: app-integration/error-code-aadsts700003-device-object-not-found.md
101103
- name: Error AADSTS7000110 - request is ambiguous, multiple application identifiers found
102104
href: app-integration/error-code-aadsts7000110-request-is-ambiguous.md
103105
- name: Error AADSTS7000112 - application is disabled

0 commit comments

Comments
 (0)