Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error AADSTS650052

AADSTS650052: the app needs a service your tenant has not subscribed to

10 min read Updated October 5, 2026 Microsoft 365 & Entra ID

Fix it now

AADSTS650052 is Microsoft telling you “The app needs access to a service that your organization hasn’t subscribed to or enabled”. There is no service principal in your tenant for the workload the application asked for, so no token can be issued against it. It is not a consent or permissions problem.

  1. In the Entra admin centre open Monitoring and health, Sign-in logs, find the failed sign-in and read the resource it was trying to reach.
  2. In Enterprise applications, All applications, set the Application type filter to All applications and search for that resource by name. Nothing returned means there is no service principal.
  3. In the Microsoft 365 admin centre open Billing, Your products and check whether that workload sits on a subscription you actually own.
  4. If the tenant does not own it, start the trial or buy the plan that contains it. The service principal is provisioned when the subscription lands.
  5. If the principal does exist, open Properties and confirm it is enabled for users to sign in, then grant admin consent under Permissions.

Retry in a private browser window afterwards so a cached token is not reused and read as a continuing failure.

If sign-in works you can stop here. If not, the next section separates this from the four codes it is most often confused with.

Why it happens

Entra ID issues tokens for resources, and a resource has to exist in your tenant as a service principal before a token can be minted against it. Service principals for Microsoft workloads are provisioned when the tenant acquires the subscription that contains them. If the tenant never had that subscription, the object was never created, and the request fails before consent, permissions or roles are even considered.

Microsoft’s published text is unusually plain for an AADSTS code: “The app needs access to a service (\”{name}\”) that your organization \”{organization}\” hasn’t subscribed to or enabled. Contact your IT Admin to review the configuration of your service subscriptions.” The name in that message is the resource, and it is the single most useful thing on the screen – it tells you exactly what to go and look for.

The neighbouring codes describe the same shape of failure at different points. AADSTS500011 is InvalidResourceServicePrincipalNotFound: the resource principal was not found in the named tenant, which can mean the application was never installed by an administrator, never consented to by any user, or – the one people forget – that the authentication request went to the wrong tenant altogether. AADSTS500014 is InvalidResourceServicePrincipalDisabled: the service principal exists but is disabled, which Microsoft says indicates either a subscription within the tenant having lapsed or an administrator having deliberately disabled the application’s service principal.

That distinction is worth holding on to. 650052 means the object was never there. 500014 means it is there and switched off, and one of the two causes for that is a licence that used to be paid for and no longer is. AADSTS50001, InvalidResource, is blunter still – “The resource is disabled or doesn’t exist” – and Microsoft’s remedy points at the application’s own code and the exact resource URL it is requesting. AADSTS650054 is the tidying-up case: the application is still asking for permissions to a resource that has been removed or is no longer available.

The tenant has never had the subscription

You have this one if AADSTS650052 naming a workload nobody in the organisation has bought, often after a supplier’s application was pointed at your tenant.

  1. Read the resource name from the error or from the sign-in log.
  2. Check Billing, Your products for a subscription that contains it. A trial counts.
  3. Start a trial of the plan that includes it, or buy it, and retry once provisioning has completed.
  4. Confirm the service principal now exists under Enterprise applications, All applications.

Provisioning is not instant. Give it time before concluding the subscription did not help.

A subscription inside the tenant has lapsed

You have this one if AADSTS500014, on an application that worked until recently.

  1. Check Billing, Your products for a subscription that has expired or been disabled.
  2. Renew it, and confirm the service principal returns to enabled.
  3. If billing is healthy, check whether an administrator disabled the application under Enterprise applications, Properties, Enabled for users to sign-in.

The resource principal was never provisioned or consented

You have this one if AADSTS500011 naming a resource that does exist as a product but has never been used in this tenant.

  1. Search Enterprise applications, All applications with the Application type filter set to All applications – the default view hides some objects.
  2. If nothing is there, have an administrator install or consent to the application so the service principal is created.
  3. Check the tenant the request was sent to. A request aimed at the wrong tenant produces this code with everything else correct.

The application is asking for the wrong resource

You have this one if AADSTS50001 or AADSTS650054, usually from an in-house or supplier-built application rather than a Microsoft one.

  1. Read the exact resource identifier from the sign-in log and compare it against what the application’s code requests.
  2. For AADSTS650054, remove permissions to resources that no longer exist from the app registration.
  3. Have the developer confirm the resource URL against Microsoft’s current documentation – resource identifiers do get retired.

Full reference

Five codes, five different situations

Code Published meaning Where the fix is
AADSTS650052 The app needs a service the organisation has not subscribed to or enabled Billing – acquire the subscription
AADSTS500011 InvalidResourceServicePrincipalNotFound – the resource principal was not found in the tenant Install or consent to the app, or check you are hitting the right tenant
AADSTS500014 InvalidResourceServicePrincipalDisabled – a subscription lapsed, or an admin disabled the service principal Billing, or the application’s Properties
AADSTS50001 InvalidResource – the resource is disabled or does not exist The application’s own code and resource URL
AADSTS650054 The app asked for permissions to a resource that has been removed The app registration’s API permissions

Reading the sign-in log properly

  • Filter to failures and find the exact entry by time and username rather than by error text.
  • Open the entry and read the Resource name and Resource ID. The resource is what is missing, not the application.
  • Check the Application ID as well. A supplier’s application and its resource are often different objects.
  • Look at the Conditional Access tab on the same entry. A policy failure produces a different code, and ruling it out takes seconds.

Confirming a service principal exists

The Enterprise applications list defaults to a filtered view that does not show everything. Set the Application type filter to All applications before concluding an object is absent, otherwise you will buy a subscription for a workload the tenant already owns.

What will not fix this

  • Granting admin consent. Consent applies to an object that exists; it cannot create one.
  • Adding API permissions in the app registration. Same reason.
  • Registry changes, client reinstalls or cache clearing. This decision is taken in the directory, not on the device.
  • Adding the user to a role. Roles govern what a principal may do, not whether a resource exists.
  • Assigning a licence to the user, if the tenant does not hold the subscription at all. The subscription has to exist before seats can be assigned from it.

Before you buy

Two checks save money here. First, confirm the resource is genuinely a Microsoft workload sold on a plan rather than a third-party application that simply needs consent – the error text names it, so this takes a minute. Second, check whether an existing subscription already contains it under a different name; Microsoft workloads move between bundles and are frequently already owned. Start a trial before a purchase where one is available, because the trial provisions the same service principal and proves the diagnosis for nothing.

When a licence is the actual fix

This is one of the few errors where a licence really is the fix. No registry key, consent grant or policy change creates a service principal for a workload the tenant has never subscribed to, and until the subscription lands the sign-in cannot succeed. Which subscription depends entirely on the resource named in the error, so read that first and start a trial of the plan containing it before committing – the trial provisions the same service principal and proves the diagnosis at no cost. Microsoft 365 E3 covers the majority of these cases because it carries the Entra ID, Exchange, SharePoint and Office service plans that business applications resolve against, but it is not automatically the right answer. Send us the resource name from your sign-in log and we will tell you which plan actually contains it, then supply licences only for the users who need it.

Every code this article covers

Code What it points at Source
AADSTS650052 “The app needs access to a service that your organization hasn’t subscribed to or enabled” – there is no service principal for that workload in the tenant Microsoft Learn
AADSTS500011 InvalidResourceServicePrincipalNotFound – the resource principal was not found in the named tenant; the application may never have been installed or consented to, or the request went to the wrong tenant Microsoft Learn
AADSTS500014 InvalidResourceServicePrincipalDisabled – the service principal for the resource is disabled, indicating a lapsed subscription within the tenant or an administrator having disabled it Microsoft Learn
AADSTS50001 InvalidResource – the resource is disabled or does not exist; check the application’s code for the exact resource URL it requests Microsoft Learn
AADSTS650054 The application asked for permissions to access a resource that has been removed or is no longer available Microsoft Learn

Confirm the fix worked

  1. The resource named in the error now appears under Enterprise applications, All applications with the type filter set to All applications.
  2. Billing, Your products shows an active subscription containing that workload.
  3. The application’s service principal shows Enabled for users to sign-in set to Yes.
  4. A test sign-in in a private browser window completes without AADSTS650052.
  5. The sign-in log records a success for the same user, application and resource.

Questions people ask about this

Can admin consent fix AADSTS650052?

No. Consent applies to a service principal that already exists in the tenant. This error means the object was never created because the tenant never had the subscription that provisions it.

How do I know which plan I need?

Read the resource name out of the error text or the sign-in log; that is the workload. Check it against Billing, Your products before buying, because Microsoft workloads move between bundles and are frequently already owned under a different name.

What is the difference between 650052 and 500014?

650052 means the service principal was never created because the tenant never subscribed. 500014 means it exists and is disabled – either a subscription inside the tenant has lapsed, or an administrator switched the application off.

Will a trial subscription prove the diagnosis?

Yes, and it is the cheapest way to do so. A trial provisions the same service principal as a paid subscription, so if the sign-in starts working the diagnosis is confirmed before any money changes hands.

The app is from a supplier, not Microsoft. Is this still a subscription problem?

Read the resource, not the application. Suppliers’ applications routinely request Microsoft workloads as resources, and this error is about the resource. If the named resource is a Microsoft service your tenant does not own, the answer is the same.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error 554 5.2.2 mailbox full: Exchange Online is refusing mail for the user License Error Autopilot 0x801c03f3 and 8018000A: device record missing or already claimed Free Fix LargeObject and ExceededAllowedLength: Entra ID rejects an oversized object License Error 0x80043003 and 0x80cf0440: the subscription is deleted or suspended and enrolment stops
โ† Back to Knowledge Base