Tag not monitored by Microsoft.
The error message indicates that the school’s Microsoft Entra ID (tenant webmailbyui.onmicrosoft.com) has a tenant restrictions policy that blocks sign-in from other organizations’ tenants. In practice, this means:
- The organization only allows specific tenants/accounts to access its resources.
- A personal Microsoft account (such as a Gmail-based Microsoft account) is being blocked by that policy when trying to reach the Azure portal.
- Only the organization’s administrator can change this policy or grant an exception.
Based on the provided information, the supported options are:
- Contact the school’s IT / tenant administrator
The message explicitly states that access is blocked by an organization security policy and that only the administrator can update it. The documented guidance for this scenario is:- Sign-in is blocked by a security policy called tenant restrictions, which allows sign-in only to selected organizations.
- Only the work or school account organization’s administrator can update this policy to unblock access to other organizations.
- To request access, provide the administrator with:
- The account being used (personal Microsoft account created on the Gmail address).
- The target organization/tenant that needs to be accessed (Azure for Students / Azure portal).
- Follow institution guidance on which email to use
For Azure Dev Tools for Teaching and similar education offers, the documented behavior is:- Students must have a Microsoft account.
- If the domain is associated with Active Directory, accounts under that domain are already considered Microsoft accounts.
- If using a university email, a Microsoft account must be created with that email address, or a personal email must be linked as a Microsoft account.
- If sign-in issues persist, validate account and sign-in details
If the tenant restriction is adjusted by the admin but sign-in still fails, the following general sign-in checks apply:- Ensure the correct portal URL is used (for example,
https://myapps.microsoft.comor a tenant-specific URL if the organization provides one). - Confirm that the password is valid and not expired.
- Ensure security/verification info (phone, alternate email) is current.
- Clear browser cache or try a different browser or InPrivate/Incognito session.
- Ensure the correct portal URL is used (for example,
There is no client-side method to bypass tenant restrictions. Resolution requires the webmailbyui.onmicrosoft.com administrator to either:
- Add an exception for the personal Microsoft account/tenant that needs Azure for Students access, or
- Provide an alternative, such as using a school-managed account that is already allowed by their tenant restrictions policy.
References: