web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Pages / Tenant Guest Users Nee...
Power Pages
Answered

Tenant Guest Users Need Admin Approval to Complete Registration

(0) ShareShare
ReportReport
Posted on by

Hello,

 

I've come across an issue in my Production Portal (Power Pages) solution.  I have configured the authentication for users to use Azure AD (Entra ID).  In my Sandbox environment and Portal, this works perfectly for all Tenant users (members and guests).  However, I have recently deployed the portal to a Production environment, and only members are able to complete the invitation process.  Guest users get the invitation code, register it with their contact profile, and then go through the MFA setup process only to see a message saying Approval required. The Sandbox environment was created a year ago, and the Production environment was created back in August 2023.  Does anyone know why Guest users can sign in with Azure AD in the Sandbox version but not the Production version?  Is there a setting in Dynamics 365 that I need to change that I forgot?  This doesn't seem like an Azure AD (Entra ID) thing.  Any assistance would be greatly appreciated!

 

KyleSchroeder_0-1701630556691.png

 

Categories:
I have the same question (0)
  • Fubar Profile Picture
    8,435 Super User 2025 Season 2 on at

    The Message you are seeing is an Azure message.  I can't remember where the setting is exactly, but think it is to do with the Consent workflow, in Azure locate the Application that will exist for the Portal/Power Pages site and you configure it for the Azure Application. 

     

  • KyleSchroeder Profile Picture
    on at

    Can you elaborate a little more on "Configure it for the Azure Application"?  When I go to Azure and find both Portals in App Registration under Applications, they both have identical configurations and I don't see anything that stands out.  I know this didn't need to done for the Sandbox version or the other Portals solutions I've built and migrated.

  • Verified answer
    KyleSchroeder Profile Picture
    on at

    I've found the solution to my issue, and I hope this will help everyone else.  The cause behind this issue is due to the creator of the Portal/Power Pages site.  The account I was using to create the Production version did not have enough permissions in Azure/Entra, so it was not prompted to approve access to the Microsoft Graph API.  This meant that I needed someone with Global Admin permission to go to Azure AD/Entra ID and follow these steps.

    • Go to entra.microsoft.com
    • Under Applications, select App Registration
    • Search for the name of the Portal/Power Pages and click on the name
    • Go to the API permissions
    • If the APIs have not been approved, the Global Admin needs to click Grant admin consent for <Company Name>

    Once the last step has been completed, it should allow guest users in the tenant to use Azure AD as their OpenID connection and authenticator.  In the future, I'll be looking to use Google and/or Microsoft as alternative authenticators.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Power Pages

#1
Fubar Profile Picture

Fubar 93 Super User 2025 Season 2

#2
Jerald Felix Profile Picture

Jerald Felix 45

#3
Lucas001 Profile Picture

Lucas001 28 Super User 2025 Season 2

Last 30 days Overall leaderboard