Set up sign-in for multi-tenant Azure Active Directory using custom policies in Azure Active Directory B2C

I have following the tutorial


I have a button showing up and it looks like it works but when I login with a work account I get

Selected user account does not exist in tenant 'Default Directory' and cannot access the application '' in that tenant. The account needs to be added as an external user in the tenant first. Please use a different account.

It seems to work with a gmail account but not another tenant's account.

My question is how do I get it to work with another tenants account

I tried to reproduce the same in my environment and got the same error as below:


To resolve the error, please try the below:

I created an Azure AD Application and configured redirect URI:


Now, I created a Policy Key like below:


To configure Azure AD as Identity Provider, I added the ClaimsProvider in the TrustFrameworkExtensions.xml file like below:

<DisplayName>Common AAD</DisplayName>
<TechnicalProfile Id="AADCommon-OpenIdConnect">
<DisplayName>Common AAD</DisplayName>
<Description>Login with your Contoso account</Description>
<Protocol Name="OpenIdConnect"/>
<Item Key="METADATA">https://login.microsoftonline.com/testaadb2c.onmicrosoft.com/v2.0/.well-known/openid-configuration</Item>
<!-- Update the Client ID below to the Application ID -->
<Item Key="client_id">CLIENTID</Item>
<Item Key="response_types">id_token</Item>
<Item Key="scope">openid profile</Item>
<Item Key="response_mode">form_post</Item>
<Item Key="HttpBinding">POST</Item>
<Item Key="UsePolicyInRedirectUri">false</Item>
<Item Key="DiscoverMetadataByTokenIssuer">true</Item>
<Item Key="ValidTokenIssuerPrefixes">https://login.microsoftonline.com/</Item>
<Key Id="client_secret" StorageReferenceId="B2C_1A_AADAppSecret"/>
<UseTechnicalProfileForSessionManagement ReferenceId="SM-SocialLogin"/>
<DisplayName>Azure Active Directory</DisplayName>
<TechnicalProfile Id="AAD-Common">
<DisplayName>Azure Active Directory</DisplayName>
<Item Key="ApplicationObjectId">OBJECTID</Item>
<Item Key="ClientId">CLIENTID</Item>
<DisplayName>Local Account SignIn</DisplayName>
<TechnicalProfile Id="login-NonInteractive">
<Item Key="client_id">CLIENTID</Item>
<Item Key="IdTokenAudience">AUDIENCE</Item>
<InputClaim ClaimTypeReferenceId="client_id" DefaultValue="XXXXXX"/>
<InputClaim ClaimTypeReferenceId="resource_id" PartnerClaimType="resource" DefaultValue="XXXXXX"/>


When I run the custom Policy, I got the login screen successfully like below:


When I tried to login with AzureAD User account , I am able to sign-in successfully like below:



