Forum Discussion

HannesDecortePionira's avatar
HannesDecortePionira
Copper Contributor
Oct 05, 2026

AADSTS500571 in Visual Studio to Azure Resource Manager; guest account disabled in resource tenant

An account is unable to sign in through Visual Studio to Azure Resource Manager. The sign-in fails with V2Error: invalid_grant AADSTS500571: The guest user account is disabled

Findings so far

The local account is active in the home tenant.
The error indicates that the guest user object is disabled in the resource tenant, not in the home tenant.
The resource Tenant is 72f988bf-86f1-41af-91ab-2d7cd011db47. That is the Microsoft Tenant.
How can I be a guest user on the Microsoft Tenant?

How do I resolve the issue.

Application and resource:

Application: Visual Studio
Application ID: 04f0c....
Resource: Azure Resource Manager
Resource ID: 797f4846-ba00-4fd7-ba43-dac1f8f63013

Tenant details:

Home tenant ID: f48xxx (The Tenant of the User that is unable to sign-in.
Resource tenant ID: 72f988bf-86f1-41af-91ab-2d7cd011db47

Diagnostic details:

Error code: AADSTS500571
Findings so far:

The local account is active in the home tenant.
The error indicates that the guest user object is disabled in the resource tenant, not in the home tenant.

1 Reply

  • The failure is not saying that your home account is disabled. AADSTS500571 means the guest object in the resource tenant is disabled, and the tenant ID shown is Microsoft’s own tenant, so Visual Studio is probably reusing a cached tenant association instead of authenticating against the tenant that owns your subscription. Sign out of every account in Visual Studio, remove the affected identity under Account Settings, close Visual Studio, and clear its cached Azure credentials. In a terminal, run az account clear, then sign in explicitly with az login --tenant <your-home-tenant-id> and confirm the expected subscription with az account show. Reopen Visual Studio, add only the correct work account, and select that subscription. You cannot enable a disabled guest yourself; only the resource tenant can do that. If Visual Studio still requests Microsoft’s tenant, capture the correlation ID and timestamp and open a Visual Studio authentication support case.