Microsoft 365 Admin Decoder Fast answers for working admins
AADSTS700016

Application was not found in the directory

Answer: The application identifier in the authentication request was not found in the target tenant.
Resolution playbook

Fix it, then prove it

Use the error record as the starting point; use tenant evidence to confirm the actual cause.

1

Likely causes

  • A correct client ID sent to the wrong tenant produces the same practical symptom.
  • Conditional Access, MFA, identity risk, session, tenant routing, or account state changed the authentication decision.
  • The sign-in used a different application, resource, device, location, or authentication flow than the working comparison.
2

Recommended fix

  1. Confirm the client ID exactly matches the app registration.
  2. Confirm the authority or tenant ID points to the intended directory.
  3. Verify the application was not deleted and that a service principal exists when required.
3

Verify

  1. Repeat the sign-in using the intended tenant and supported interactive or non-interactive flow.
  2. In Entra sign-in logs, confirm the new event succeeds and review Authentication Details and Conditional Access tabs.
  3. If a policy was changed, confirm the expected policy result using report-only or What If before broad rollout.
4

Escalate when

  • The failure persists after the documented prerequisites and a new authentication/session attempt.
  • Multiple users, apps, devices, or networks show the same error, suggesting tenant policy or service scope.
  • You can provide the exact UTC time, tenant, application/resource, correlation or request ID, and sanitized logs.
Capture the support evidence
Error code: AADSTS700016
UTC timestamp: <yyyy-mm-dd hh:mm:ssZ>
Correlation ID: <guid>
Tenant ID: <guid>
Application / resource: <name>

Template only. Fill it from the failed sign-in and keep user identifiers out of public tickets.

Admin context

A correct client ID sent to the wrong tenant produces the same practical symptom.

Evidence to preserve

  • UTC timestamp and correlation/request ID
  • Tenant, application, resource, and authentication flow
  • Sanitized service log details and exact operation
Advertisement