Fix Azure VM Creation Error AADSTS16000 (Interaction Required)
Question details
The user is unable to create an Azure virtual machine due to a tenant access error preventing application access.

- Product
- Microsoft Azure
- Device & OS
- not provided
- Scenario
- Attempting to create an Azure virtual machine in the Azure portal.
- Observed behavior
- An AADSTS16000 interaction_required error is displayed, indicating the logged-in live.com account is not present in the Microsoft Services tenant.
Verify whether you are currently logged into the Azure portal using a personal Microsoft account (such as @live.com or @outlook.com) instead of your official corporate Azure Active Directory account.
Switch to an Appropriate Azure Active Directory Account
Resolve the error by signing out of your personal account and logging in with an account that belongs to the target Azure tenant.
The AADSTS16000 error typically occurs when your browser automatically signs you in with a personal Microsoft account instead of the organizational account required for accessing specific Azure resources.
Click on your profile picture or initials in the top right corner of the Azure Portal and select 'Sign out'.
Open a new Incognito or InPrivate browsing window to prevent automatic sign-in using cached credentials.
Navigate back to the Azure Portal and sign in using your corporate Azure Active Directory (Azure AD) email and password.

Request Guest Access from the Tenant Administrator
If you must use your live.com account, it needs to be added as a guest user in the target Microsoft Services tenant.
Submit an Azure Support Request
Use the official Microsoft Azure support channels if you have proper directory access but the error persists.
Keep Your Work Flowing with WPS Office
While resolving complex Azure Active Directory tenant issues, don't let your documentation and reporting slow down. WPS Office provides a free, seamless, and lightweight solution to manage all your work documents without the hassle of account conflicts.
- 1. Download and Install: Visit the official WPS website to download the lightweight installer and set up the suite in minutes.
- 2. Open Your Files: Instantly open, edit, and save your existing Microsoft Word, Excel, or PowerPoint documents with full format compatibility.
- 3. Draft Technical Documents: Use WPS Writer to document your Azure deployment steps or WPS Spreadsheet to plan your VM configurations without relying on cloud access.

Frequently Asked Questions
What exactly does the AADSTS16000 error mean?
The AADSTS16000 error indicates an authentication issue where the current user session (such as a live.com account) requires additional interaction, or the account is not recognized as a valid member of the target Microsoft Services tenant trying to be accessed.
Can I manage Azure virtual machines with a personal live.com account?
Yes, but only if that personal account has been formally invited as a Guest user to an organization's Azure Active Directory tenant, and assigned the proper Role-Based Access Control (RBAC) permissions to create or manage resources.
How do I switch directories in the Azure portal?
Click the 'Directories + subscriptions' icon in the top toolbar of the Azure portal. In the panel that opens, select the correct directory (tenant) where you have the permissions to create virtual machines.
Why does my browser keep signing me into the wrong Microsoft account?
Browsers cache login credentials and session cookies. If you frequently use personal Microsoft services like Outlook or Xbox, the browser may default to that account. Using Private/Incognito windows or dedicated browser profiles can prevent this.




