SOLVED
Home

Cannot login using ServicePrincipal: Application was not found in the directory

%3CLINGO-SUB%20id%3D%22lingo-sub-146425%22%20slang%3D%22en-US%22%3ECannot%20login%20using%20ServicePrincipal%3A%20Application%20was%20not%20found%20in%20the%20directory%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-146425%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20trying%20to%20set%20up%20an%20automation%20script%20that%20allows%20me%20to%20start%20up%20and%20shut%20down%20virtual%20machines%20in%20Azure%20without%20any%20user%20input.%20I've%20created%20an%20application%20registration%20(Web%20app%20%2F%20API)%20in%20Azure%20AD%20and%20in%20Subscriptions%20I've%20assigned%20the%20Virtual%20Machine%20Contributor%20role.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20application%20ID%20is%3A%20a8faf7f8-a0c2-4c03-8989-0a2d32915cd9%3C%2FP%3E%0A%3CP%3EThe%20tenant%20ID%20is%3A%20696c6a65-a325-4af4-bfc4-f67a88425e4b%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20have%20assigned%20a%20credential%20to%20the%20ServicePrincipal%3A%3C%2FP%3E%0A%3CPRE%3ENew-AzureRmADSpCredential%20-ServicePrincipalName%20https%3A%2F%2Fmydomain.com%2F0f7b7873-2354-48ad-9ee4-9e6cfefd04d4%20-Password%20%22mypassword%22%3C%2FPRE%3E%0A%3CP%3EI%20try%20to%20log%20in%20as%20follows%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%24applicationid%20%3D%22a8faf7f8-a0c2-4c03-8989-0a2d32915cd9%22%0A%24principalPassword%20%3D%20ConvertTo-SecureString%20%22mypassword%22%20-AsPlainText%20-Force%0A%24psCred%20%3D%20New-Object%20System.Management.Automation.PSCredential(%24applicationid%2C%20%24principalPassword)%3CBR%20%2F%3E%0ALogin-AzureRmAccount%20-Credential%20%24psCred%20-ServicePrincipal%20-TenantId%20696c6a65-a325-4af4-bfc4-f67a88425e4b%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBut%20when%20I%20do%2C%20I%20get%20the%20following%20error%20message%3A%20%3CSTRONG%3ELogin-AzureRmAccount%20%3A%20AADSTS70001%3A%20Application%20with%20identifier%20'8faf7f8-a0c2-4c03-8989-0a2d32915cd9'%20was%20not%20found%20in%20the%20directory%20696c6a65-a325-4af4-bfc4-f67a88425e4b%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CP%3EI%20am%20100%25%20sure%20that%20both%20the%20Application%20ID%20and%20Tenant%20ID%20are%20correct.%20What%20am%20I%20doing%20wrong%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-146425%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-146683%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20login%20using%20ServicePrincipal%3A%20Application%20was%20not%20found%20in%20the%20directory%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-146683%22%20slang%3D%22en-US%22%3E%3CP%3EI%20just%20figured%20out%20what%20was%20causing%20this.%20I%20was%20using%20the%20Linux%20version%20of%20Powershell%20which%20was%20causing%20this%20error%20message.%20Your%20instructions%20did%20work%20on%20the%20Windows%20Powershell.%20Thanks!%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-146541%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20login%20using%20ServicePrincipal%3A%20Application%20was%20not%20found%20in%20the%20directory%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-146541%22%20slang%3D%22en-US%22%3E%3CP%3ENot%20sure%20what's%20going%20on%2C%20can%20you%20send%20a%20screenshot%20of%20the%20process%20like%20I%20did%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EDon't%20forget%20to%20block%20out%20tenant%20and%20application%20if%20they%20are%20in%20production.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAlso%20you%20can%20get%2Fconfirm%20you%20tenant%20name%20from%20the%20Active%20Directory%20section.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F27047iFA052639A2D19E14%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%222018-01-18%2013_46_03.png%22%20title%3D%222018-01-18%2013_46_03.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-146507%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20login%20using%20ServicePrincipal%3A%20Application%20was%20not%20found%20in%20the%20directory%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-146507%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20getting%20the%20following%20error%20message%3A%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EAdd-AzureRmAccount%20%3A%20AADSTS50001%3A%20The%20application%20named%20%3CA%20href%3D%22https%3A%2F%2Flogin.microsoftonline.com%2F696c6a65-a325-4af4-bfc4-f67a88425e4b%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Flogin.microsoftonline.com%2F696c6a65-a325-4af4-bfc4-f67a88425e4b%2F%3C%2FA%3E%20was%20not%20found%20in%20the%20tenant%20named%20696c6a65-a325-4af4-bfc4-f67a88425e4b.%20This%20can%20happen%20if%20the%20application%20has%20not%20been%20installed%20by%20the%20administrator%20of%20the%20tenant%20or%20consented%20to%20by%20any%20user%20in%20the%20tenant.%20You%20might%20have%20sent%20your%20authentication%20request%20to%20the%20wrong%20tenant.%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI've%20triple%20checked%26nbsp%3Bthat%20I'm%20using%20the%20correct%20application%20ID%2C%20principle%20name%20and%20tenant%20ID.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-146480%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20login%20using%20ServicePrincipal%3A%20Application%20was%20not%20found%20in%20the%20directory%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-146480%22%20slang%3D%22en-US%22%3E%3CP%3EI%20got%20an%20error%20on%20the%20password%2C%20below%20was%20successful%20for%20me%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F27041i19116A4F92B8BF27%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%2220180118-110343.png%22%20title%3D%2220180118-110343.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%24principalPassword%20%3D%20ConvertTo-SecureString%20%22mypassword123%22%20-AsPlainText%20-Force%0ANew-AzureRmADSpCredential%20-ServicePrincipalName%20https%3A%2F%2Fdomain.com%2Fxxxxxxxxxxxxx%20-Password%20%24principalPassword%20%0A%0A%24applicationid%20%3D%22d35a3b69-98f8-4dbb-abf8-1660ed11fadd%22%0A%24psCred%20%3D%20New-Object%20System.Management.Automation.PSCredential(%24applicationid%2C%20%24principalPassword)%0A%0AAdd-AzureRmAccount%20-Credential%20%24psCred%20-ServicePrincipal%20-TenantId%206f0ebec4-xxxx-xxxx-xxxx-xxxxxxxxxxxxxxxxx%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-146474%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20login%20using%20ServicePrincipal%3A%20Application%20was%20not%20found%20in%20the%20directory%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-146474%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Hannel%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIt%20did%20not%20show%20any%20error%20message%20when%20issuing%20that%20command.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-146462%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20login%20using%20ServicePrincipal%3A%20Application%20was%20not%20found%20in%20the%20directory%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-146462%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20Roy%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhen%20you%20set%20the%20credential%20was%20it%20successful%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3ENew-AzureRmADSpCredential%20-ServicePrincipalName%20https%3A%2F%2Fmydomain.com%2F0f7b7873-2354-48ad-9ee4-9e6cfefd04d4%20-Password%20%22mypassword%22%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Roy Hochstenbach
New Contributor

I'm trying to set up an automation script that allows me to start up and shut down virtual machines in Azure without any user input. I've created an application registration (Web app / API) in Azure AD and in Subscriptions I've assigned the Virtual Machine Contributor role.

 

The application ID is: a8faf7f8-a0c2-4c03-8989-0a2d32915cd9

The tenant ID is: 696c6a65-a325-4af4-bfc4-f67a88425e4b

 

I have assigned a credential to the ServicePrincipal:

New-AzureRmADSpCredential -ServicePrincipalName https://mydomain.com/0f7b7873-2354-48ad-9ee4-9e6cfefd04d4 -Password "mypassword"

I try to log in as follows:

 

 

$applicationid ="a8faf7f8-a0c2-4c03-8989-0a2d32915cd9"
$principalPassword = ConvertTo-SecureString "mypassword" -AsPlainText -Force
$psCred = New-Object System.Management.Automation.PSCredential($applicationid, $principalPassword)
Login-AzureRmAccount -Credential $psCred -ServicePrincipal -TenantId 696c6a65-a325-4af4-bfc4-f67a88425e4b

 

But when I do, I get the following error message: Login-AzureRmAccount : AADSTS70001: Application with identifier '8faf7f8-a0c2-4c03-8989-0a2d32915cd9' was not found in the directory 696c6a65-a325-4af4-bfc4-f67a88425e4b

I am 100% sure that both the Application ID and Tenant ID are correct. What am I doing wrong?

6 Replies

Hello Roy,

 

When you set the credential was it successful?

 

New-AzureRmADSpCredential -ServicePrincipalName https://mydomain.com/0f7b7873-2354-48ad-9ee4-9e6cfefd04d4 -Password "mypassword"

 

Hi Hannel,

 

It did not show any error message when issuing that command. 

Solution

I got an error on the password, below was successful for me

20180118-110343.png

 

 

 

$principalPassword = ConvertTo-SecureString "mypassword123" -AsPlainText -Force
New-AzureRmADSpCredential -ServicePrincipalName https://domain.com/xxxxxxxxxxxxx -Password $principalPassword 

$applicationid ="d35a3b69-98f8-4dbb-abf8-1660ed11fadd"
$psCred = New-Object System.Management.Automation.PSCredential($applicationid, $principalPassword)

Add-AzureRmAccount -Credential $psCred -ServicePrincipal -TenantId 6f0ebec4-xxxx-xxxx-xxxx-xxxxxxxxxxxxxxxxx

 

I'm getting the following error message: 

Add-AzureRmAccount : AADSTS50001: The application named https://login.microsoftonline.com/696c6a65-a325-4af4-bfc4-f67a88425e4b/ was not found in the tenant named 696c6a65-a325-4af4-bfc4-f67a88425e4b. This can happen if the application has not been installed by the administrator of the tenant or consented to by any user in the tenant. You might have sent your authentication request to the wrong tenant.

 

I've triple checked that I'm using the correct application ID, principle name and tenant ID.

Not sure what's going on, can you send a screenshot of the process like I did?

 

Don't forget to block out tenant and application if they are in production.

 

Also you can get/confirm you tenant name from the Active Directory section.

 

2018-01-18 13_46_03.png

 

 

I just figured out what was causing this. I was using the Linux version of Powershell which was causing this error message. Your instructions did work on the Windows Powershell. Thanks! :)