logo
search
list

Table of Content

Fix AADSTS50020 When Opening Files from Another Microsoft 365 Tenant

Posted by Algirdas Jasaitis

calendar

2026-08-30

views

868

likes

59

Fix AADSTS50020: Cannot Open Shared Files in Microsoft 365 Desktop Apps

Learn how to resolve error AADSTS50020 when opening shared Microsoft 365 files by forcing guest authentication and configuring Entra ID tenant settings.

Encountering an access blocked message when trying to collaborate can be incredibly frustrating, especially when you know you have permission to view or edit the document.

Problem Description: Cross-Tenant Access Blocked

The AADSTS50020 error typically triggers when you attempt to open a file shared from an external Microsoft 365 or Microsoft Entra tenant using your local Office desktop applications. Instead of properly recognizing your permissions as a guest user, the desktop software attempts to authenticate using your primary (home-tenant) credentials. Because your home credentials do not exist in the external organization's directory, access is denied and the login fails.

Quick Answer for External File Authentication Failures

To bypass this credential mismatch instantly, open the shared document link in Office for the web using an incognito browser window, sign in explicitly with your guest account, and then click "Open in Desktop App" from the ribbon.

Likely Causes Behind Error Code AADSTS50020

  • Default Application Credentials: Office desktop apps default to the primary account linked to your Windows profile or Office license, ignoring the required guest token.
  • Unredeemed B2B Invitations: You are trying to access the file before formally accepting the external organization's guest invitation.
  • Stale Cached Tokens: Conflicting login sessions stored in your system's Credential Manager are forcing the wrong identity.
  • Strict Entra ID Policies: The host organization's Cross-Tenant Access Settings or inbound trust configurations are restricting your specific domain.

Recommended Solution: Forcing Guest Authentication via Web Apps

  1. Close any currently open Microsoft Word, Excel, or PowerPoint desktop applications.
  2. Open a Private or Incognito browsing window (e.g., Ctrl+Shift+N in Chrome or Edge) to prevent automatic background sign-ins.
  3. Paste the shared file link into the address bar and press Enter.
  4. When prompted, authenticate using the exact email address that received the sharing invitation. Ensure you complete any required multi-factor authentication (MFA).
  5. Once the document successfully loads in Office for the web, locate the ribbon at the top of the screen.
  6. Click the Editing, Viewing, or Open in Desktop App button (the exact wording varies depending on the app and your permissions).
  7. When prompted by your browser to launch the external application, click Allow or Open. This securely passes the correct guest token from the web browser to your local desktop software.

Alternative Solutions for Permanent Entra ID Fixes

  1. Clear Local Office Credentials: Open the Windows Start menu, search for Credential Manager, and select Windows Credentials. Scroll down to the "Generic Credentials" section and remove any entries starting with MicrosoftOffice16_Data. Restart your PC and try opening the file again.
  2. Accept the B2B Invitation Properly: Search your email inbox for the original "You have been invited to access applications in [Organization]" email. Click the redemption link and follow the prompts to register your guest account before accessing individual files.
  3. For IT Administrators (Cross-Tenant Configuration): The host organization's Entra administrator should log into the Microsoft Entra admin center, navigate to External Identities > Cross-tenant access settings, and verify that B2B collaboration inbound access is permitted for the guest user's domain. Inbound trust settings for MFA may also need to be reviewed.

Working with WPS Office: A Seamless Local Alternative

Because Error AADSTS50020 is strictly tied to Microsoft's cloud authentication framework (Entra ID), WPS Office cannot directly bypass external tenant permission blocks. However, if live cloud collaboration isn't strictly necessary, WPS Office serves as an excellent, free alternative for local document management. You can ask the file owner to download a local copy of the document and send it to you via email or a direct file transfer. Once downloaded, you can use WPS Office to flawlessly open, edit, and save Word, Excel, and PowerPoint files on your machine without dealing with complex cloud tenant logins or credential conflicts.

Prevention Tips for B2B Collaboration Errors

  • Always establish your guest identity by opening initial external sharing links in a web browser before transitioning to desktop apps.
  • Set up a dedicated browser profile specifically for external client or partner collaboration to isolate cookies and login tokens.
  • Regularly update your Office desktop applications, as Microsoft frequently patches cross-tenant authentication handoffs.

FAQs About Microsoft 365 Guest Access Issues

Why does the shared file open fine in my browser but fail in the desktop app?

Web browsers easily isolate web sessions, allowing you to log in cleanly as a guest. Desktop applications, however, are deeply integrated with your operating system and primary Microsoft license, which often overrides the guest token and attempts to use your home credentials instead.

Can I fix AADSTS50020 without contacting an IT administrator?

Often, yes. Utilizing the "Open in Desktop App" method from an incognito web browser usually bypasses the local credential conflict. However, if the error is caused by the external company's strict Entra ID inbound trust policies, their IT administrator will need to adjust the access settings.

Algirdas Jasaitis

15 years of office industry experience, tech lover and copywriter. Follow me for product reviews, comparisons, and recommendations for new apps and software.