How to fix AADSTS50020 for Outlook on Mac?

S Holmes 5 Reputation points
2026-08-17T14:00:16.03+00:00

My work email account moved from one domain to another but the cut-over happened without my knowledge, so I was not able to remove the old instance of the account from Outlook before the email address was already moved to the new domain. The email address has not changed. I did remove the email account from my Outlook desktop app, but now when I try to add it back in as an account to the Outlook desktop app for Mac (via Office 365 login) there is a cache problem that is using the wrong/outdated identity provider and therefore will not authenticate the account properly (error AADSTS50020).

This appears to be something specific to my computer because the account was able to be properly added to another user's Outlook app (who had never used the account before). I have worked through many possible solutions per my internet research including clearing multiple potentially relevant entries from the Keychain Access app and resetting some defaults using the terminal, but nothing is working. I am using legacy Outlook but even when I switch over to "new" Outlook for mac, it still wouldn't work. I am able to login to the webmail account using an incognito window and on my phone just fine. What other options are there for removing the cached identity provider / location so that I can re-add my account into Outlook? Would uninstalling/reinstalling Office potentially work? I have tried and tried so many potential solutions that the IT team member and my internet + ChatGPT searching have suggested. I would be eternally grateful for any additional possible solutions that could solve this issue!

EDIT: Additional error message text includes "User account 'xxxx [my email address - has not changed, just the company that owns it]' from identity provider 'https://sts.windows.net/xxxx' tenant 'xxxx [old company name]' and cannot access the application 'xxxx' (Microsoft Office) in that tenant. The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account.

EDIT 2: The email address has not changed, just the company that owns it. It is hosted by a private company and the IT professional for that company has been trying to help me with no success. I may ask them to submit a ticket with Microsoft if possible, but was hoping to find a solution I could accomplish on my own and soon.

Outlook | MacOS | Legacy Outlook for Mac | For business

Answer recommended by moderator
S Holmes 5 Reputation points
2026-09-02T17:55:03.79+00:00

@Sergi Lucas I am not sure if I found THE solution, but I was able to fix my issue by maybe "tricking" Outlook to look at the proper/updated tenant.

When attempting to login to the Outlook for Mac desktop app, I used the [aaaa]@yyyy.onmicrosoft.com where [aaaa] = username for my email address and yyyy = new tenant domain name. It may have been a cheap work around / trick, but it worked so I'm not complaining.

This was in addition to removing all of the applicable cached entries in Keychain Access per the standard answers, including some that were listed as "invisible" and needed to be included in my view. So not sure if the updated login info alone would have been sufficient, but worth a try especially if the Keychain Access options have not fixed your issue. I have restarted my computer (i.e., quit Outlook) since this fix and it still works so far. Best of luck!

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Oldest
  1. AI answer

    2026-08-17T14:00:30.2433333+00:00

    For this Outlook for Mac scenario, the supported fixes are to clear the cached Office and authentication tokens from macOS Keychain, verify the account is using the correct UPN if modern authentication is involved, and make sure Outlook is updated.

    1. Quit Outlook and all other Office apps.
    2. In Keychain Access, remove cached entries for the affected account:
      • Search for Exchange and delete all items for that Exchange account.
      • Search for adal and delete all items of type MicrosoftOffice15_2_Data:ADAL:<GUID>.
      • Search for office and delete:
        • Microsoft Office Identities Cache 2
        • Microsoft Office Identities Settings 2
    3. Quit Keychain Access.
    4. Start Outlook again and authenticate when prompted.
    5. If the mailbox is on Exchange Online with modern authentication and the sign-in keeps looping, check whether the mailbox sign-in is using the wrong identifier:
      • In Outlook Accounts, enter the UPN in the User name field instead of the email address.
      • Then quit and restart Outlook.
      • This is specifically relevant when the email address differs from the user principal name.
    6. Update Outlook for Mac. For Outlook 2016 for Mac repeated authentication prompts caused by duplicate tokens in Keychain, the documented resolution is to install the February 2017 Outlook update, version 15.31.0.
    7. Reinstalling Office is not documented here as the fix for this Outlook for Mac identity-cache issue. The documented remediation is clearing the Keychain tokens and cached Office identity entries, then signing in again.
    8. If Microsoft 365 or Office for Mac keeps asking to sign in or shows Authentication Expired, and Office was moved from the default /Applications folder, reset Keychain permissions by following the Microsoft guidance for repeated keychain access prompts.

    Because webmail works in an incognito window and the account works on another device, the issue is consistent with stale local authentication state on the Mac rather than a mailbox problem.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.