My Azure account started as a personal Microsoft account (an
@outlook.com address) that signed up for Azure. Inside the auto-created
tenant, my account existed as an external (guest / B2B) user
federated via the live.com identity provider, and it was the sole
Global Administrator / Owner.
In Microsoft Entra ID I opened my own user object and clicked
"Convert to internal user."
Since then I can no longer sign in. Every attempt with my @outlook.com
address fails with:
AADSTS50020: User account '<my outlook address>' from identity
provider 'live.com' does not exist in tenant '...' and cannot access
the application '...' in that tenant. The account needs to be added as
an external user in the tenant first.
My understanding of the cause
The "Convert to internal user" action appears to have:
- changed my UserType from Guest to Member,
- changed my UPN to an internal
…onmicrosoft.com form, and
- removed the federation to my
live.com account,
so the external identity I used to sign in no longer exists, and the new
internal account expects a tenant password I never set.
What I've already tried
- Plain
az login and az login --allow-no-subscriptions → returns an empty subscription list; az account list is empty.
- Full Microsoft sign-out + fresh incognito portal login → succeeds but lands in a different, empty default directory.
- Portal → Settings → Directories + subscriptions → All Directories → "No directories found." (My original tenant is not listed.)
- Subscriptions blade → 0 of 0 (role = all, status = all).
- Cost Management + Billing → Your subscriptions → empty; Billing scopes → empty.
- Tried signing in with guessed internal UPNs (
<alias>@<tenant>.onmicrosoft.com, the #EXT# form, admin@…) → "This username may be incorrect."
So the @outlook.com identity authenticates fine, but it has no
membership in the original tenant anymore, and I have no other admin
account to fix it from inside.
Question
How do I recover from a self-inflicted "Convert to internal user"
lockout when I am the only administrator?
- Is there any self-service way to revert the conversion, restore the external/B2B user, or set a password on the converted internal account?
- If not, what is the correct support path (subscription/billing support is free) and what proof of ownership should I prepare to get the conversion reverted?
Any guidance appreciated — I just need admin access to my own tenant and
subscription back.