Locked out after "Convert to internal user" in Entra ID — sign-in now fails with AADSTS50020

Aziz Nadirov 25 Reputation points
2026-06-15T12:17:11.8633333+00:00

My Azure account started as a personal Microsoft account (an

@outlook.com address) that signed up for Azure. Inside the auto-created

tenant, my account existed as an external (guest / B2B) user

federated via the live.com identity provider, and it was the sole

Global Administrator / Owner.

In Microsoft Entra ID I opened my own user object and clicked

"Convert to internal user."

Since then I can no longer sign in. Every attempt with my @outlook.com

address fails with:

AADSTS50020: User account '<my outlook address>' from identity

provider 'live.com' does not exist in tenant '...' and cannot access

the application '...' in that tenant. The account needs to be added as

an external user in the tenant first.

My understanding of the cause

The "Convert to internal user" action appears to have:

  • changed my UserType from Guest to Member,
  • changed my UPN to an internal …onmicrosoft.com form, and
  • removed the federation to my live.com account,

so the external identity I used to sign in no longer exists, and the new

internal account expects a tenant password I never set.

What I've already tried

  • Plain az login and az login --allow-no-subscriptions → returns an empty subscription list; az account list is empty.
  • Full Microsoft sign-out + fresh incognito portal login → succeeds but lands in a different, empty default directory.
  • Portal → Settings → Directories + subscriptions → All Directories → "No directories found." (My original tenant is not listed.)
  • Subscriptions blade → 0 of 0 (role = all, status = all).
  • Cost Management + Billing → Your subscriptions → empty; Billing scopes → empty.
  • Tried signing in with guessed internal UPNs (<alias>@<tenant>.onmicrosoft.com, the #EXT# form, admin@…) → "This username may be incorrect."

So the @outlook.com identity authenticates fine, but it has no

membership in the original tenant anymore, and I have no other admin

account to fix it from inside.

Question

How do I recover from a self-inflicted "Convert to internal user"

lockout when I am the only administrator?

  1. Is there any self-service way to revert the conversion, restore the external/B2B user, or set a password on the converted internal account?
  2. If not, what is the correct support path (subscription/billing support is free) and what proof of ownership should I prepare to get the conversion reverted?

Any guidance appreciated — I just need admin access to my own tenant and

subscription back.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Answer accepted by question author
Sridevi Machavarapu 33,820 Reputation points Microsoft External Staff Moderator
2026-06-15T12:23:37.3733333+00:00

Hello Aziz Nadirov,

It seems like you are unable to log in to the Azure Portal due to changes made to your user account’s internal/external status in Azure.

You originally signed up for the Azure tenant using your Outlook email address (******@outlook.com), which created an account in the format user123_outlook#EXT#@user123outlook.onmicrosoft.com. However, when you changed the account to an internal user, it was converted to @user123outlook.onmicrosoft.com. As a result, whenever you tried to sign in using your original Outlook email address (@outlook.com), you received the AADSTS50020 error because no tenant could be found for that account.

I have shared the more details over private message. Please check and login with that UPN.

You will be able to log in again using your updated internal account email address by signing in with your password and setting up Azure MFA.

Hope this helps! Feel free to reach out for any further queries


If this answers your query, do click Accept Answer and Yes for was this answer helpful, which may help members with similar questions.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.