Microsoft Entra ID
Troubleshooting

Troubleshoot Microsoft Entra hybrid joined devices

In brief

The hybrid join troubleshooting page was updated with revised guidance for AADSTS50034, and its date changed from July 27, 2025, to September 1, 2026.

What Entra admins need to know

Administrators should consult the updated guidance when investigating users who cannot be found in the tenant; no required configuration change is stated.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Error code Reason Resolution
AADSTS50155: Device authentication failed
  • Microsoft Entra ID is unable to authenticate the device to issue a PRT.
  • Confirm that the device isn't deleted or disabled. For more information about this issue, see Microsoft Entra device management FAQ.
  • Follow the instructions for this issue in Microsoft Entra device management FAQ to re-register the device based on the device join type.
    AADSTS50034: The user account Account does not exist in the tenant id directory Microsoft Entra ID is unable to find the user account in the tenant.
  • Ensure that the user is typing the correct UPN.
  • Ensure that the on-premises user account is being synced with Microsoft Entra ID.
  • Event 1144 (Microsoft Entra analytics logs) contains the UPN provided. This error can sometimes be mapped to STATUS_ACCOUNT_DISABLED on a Windows client. However, the account is not actually disabled. This usually happens when the Windows client sends a SAM account name to Entra STS instead of a properly formatted UPN. This issue is usually accompanied by a lack of communication with an on-prem Active Directory domain controller in Hybrid deployments. Entra-native deployments do not encounter this issue.
  • AADSTS50126: Error validating credentials due to invalid username or password.
  • The username and password entered by the user in the Windows LoginUI are incorrect.
  • If the tenant has password hash sync enabled, the device is hybrid-joined, and the user just changed the password, it's likely that the new password hasn't synced with Microsoft Entra ID.
  • To acquire a fresh PRT with the new credentials, wait for the Microsoft Entra password sync to finish.

    Common network error codes

    Daily Entra.News

    Get daily email updates

    Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

    Loading the secure signup form…