{"id":250,"date":"2019-06-15T11:23:15","date_gmt":"2019-06-15T11:23:15","guid":{"rendered":"https:\/\/www.dabbler.dk\/?p=250"},"modified":"2019-06-15T11:25:49","modified_gmt":"2019-06-15T11:25:49","slug":"external-azure-active-directory-users-and-single-sign-on-in-dynamics-365-business-central","status":"publish","type":"post","link":"https:\/\/www.dabbler.dk\/index.php\/2019\/06\/15\/external-azure-active-directory-users-and-single-sign-on-in-dynamics-365-business-central\/","title":{"rendered":"&#8220;External Azure Active Directory&#8221; users and Single-Sign-On in Dynamics 365 Business Central"},"content":{"rendered":"\n<p>If you are setting up Single-Sign-On (SSO) for Dynamics 365 Business Central (DBC) and you are only able to authenticate users local to the Azure Active Directory (i.e. non Guest or &#8220;External Azure Active Directory&#8221; users), then you might have stumbled across the same error as me.<\/p>\n\n\n\n<p>The error manifests itself by allowing you to log in using SSO, but just when the DBC webclient is suppose to open, you get this error:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"592\" height=\"298\" src=\"https:\/\/www.dabbler.dk\/wp-content\/uploads\/2019\/06\/You-user-name-or-password-is-incorrect.png\" alt=\"\" class=\"wp-image-251\" srcset=\"https:\/\/www.dabbler.dk\/wp-content\/uploads\/2019\/06\/You-user-name-or-password-is-incorrect.png 592w, https:\/\/www.dabbler.dk\/wp-content\/uploads\/2019\/06\/You-user-name-or-password-is-incorrect-300x151.png 300w\" sizes=\"auto, (max-width: 592px) 100vw, 592px\" \/><figcaption>Your user name or password is incorrect, or you do not have a valid account in Dynamics 365 Business Central.<\/figcaption><\/figure>\n\n\n\n<p>The problems is that a user with that authentication e-mails IS in fact present in DBC &#8211; so the error makes no sense.<\/p>\n\n\n\n<p>Also you will sometimes get a warning in the Event Viewer that the SSO token was valid, but the user could not be found in DBC.<\/p>\n\n\n\n<p>As mentioned the local domains works fine, it is only if you try to add external users and authenticate with those it does not work:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"475\" src=\"https:\/\/www.dabbler.dk\/wp-content\/uploads\/2019\/06\/AAD-External-User-1024x475.png\" alt=\"\" class=\"wp-image-252\" srcset=\"https:\/\/www.dabbler.dk\/wp-content\/uploads\/2019\/06\/AAD-External-User-1024x475.png 1024w, https:\/\/www.dabbler.dk\/wp-content\/uploads\/2019\/06\/AAD-External-User-300x139.png 300w, https:\/\/www.dabbler.dk\/wp-content\/uploads\/2019\/06\/AAD-External-User-768x356.png 768w, https:\/\/www.dabbler.dk\/wp-content\/uploads\/2019\/06\/AAD-External-User.png 1169w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><figcaption>User type: Guest<br>Source: External Azure Active Directory<\/figcaption><\/figure>\n\n\n\n<p>I&#8217;ve seen this error in Microsoft Dynamics 365 Business Central 2018 fall release with cumulative update 1 and 2.<\/p>\n\n\n\n<p>I&#8217;m aware that you &#8211; with powershell &#8211; can change a User type Guest to a User type Member. I tried it, but the result was the exact same. So &#8220;no cigar&#8221; for that solution.<\/p>\n\n\n\n<p>After upgrading the platform to the latest Cumulative Update (which is 7 while I&#8217;m writing this), the error is completely gone. So there you have your fix :-).<\/p>\n\n\n\n<p>Note: I&#8217;ve not tested all the CUs between 2 and 7 to figure out when it was fixed or if there is a entry in the fix list that mentions this &#8211; so if you have more knowledge about that, please share by adding a comment.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you are setting up Single-Sign-On (SSO) for Dynamics 365 Business Central (DBC) and you are only able to authenticate users local to the Azure Active Directory (i.e. non Guest or &#8220;External Azure Active Directory&#8221; users), then you might have stumbled across the same error as me. The error manifests itself by allowing you to &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.dabbler.dk\/index.php\/2019\/06\/15\/external-azure-active-directory-users-and-single-sign-on-in-dynamics-365-business-central\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;&#8220;External Azure Active Directory&#8221; users and Single-Sign-On in Dynamics 365 Business Central&#8221;<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":190,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,5],"tags":[27,32,25,24,43,26],"class_list":["post-250","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-dynamics-nav","category-software","tag-bug","tag-business-central","tag-dynamics","tag-microsoft","tag-microsoft-azure","tag-nav"],"_links":{"self":[{"href":"https:\/\/www.dabbler.dk\/index.php\/wp-json\/wp\/v2\/posts\/250","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dabbler.dk\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dabbler.dk\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dabbler.dk\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dabbler.dk\/index.php\/wp-json\/wp\/v2\/comments?post=250"}],"version-history":[{"count":3,"href":"https:\/\/www.dabbler.dk\/index.php\/wp-json\/wp\/v2\/posts\/250\/revisions"}],"predecessor-version":[{"id":255,"href":"https:\/\/www.dabbler.dk\/index.php\/wp-json\/wp\/v2\/posts\/250\/revisions\/255"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.dabbler.dk\/index.php\/wp-json\/wp\/v2\/media\/190"}],"wp:attachment":[{"href":"https:\/\/www.dabbler.dk\/index.php\/wp-json\/wp\/v2\/media?parent=250"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dabbler.dk\/index.php\/wp-json\/wp\/v2\/categories?post=250"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dabbler.dk\/index.php\/wp-json\/wp\/v2\/tags?post=250"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}