Short answer
AADSTS700016 means the application identifier in the request was not found in the directory that received it. First verify the Application (client) ID and the tenant/authority used by the app. Then confirm the app is registered in that tenant or, for a multitenant app, that the required enterprise application/service principal exists there. Grant consent only when the requested permissions and app are expected and approved.
This source-based guide is not a report of an incident investigated or reproduced by this site.
Problem / symptoms
A user or service attempts to obtain a token, but Entra reports that it cannot find the application in the named directory. This can happen before user assignment or API permission details become relevant.
Exact error
AADSTS700016: Application with identifier ‘
’ was not found in the directory ‘ ’.
The wording can also say the application has not been installed by an administrator or consented to, or that the request may have been sent to the wrong tenant.
Environment and scope
Microsoft Entra app registrations and OAuth/OIDC token requests, including daemon applications using Microsoft.Identity.Web. The exact cause depends on whether the app is single-tenant, multitenant, or Microsoft-owned.
What the evidence establishes
Microsoft documents an invalid ClientId or an app that is not registered in the specified tenant as causes. The Entra error reference also describes a missing client application in the tenant. This code by itself does not prove that admin consent is the fix.
Investigation
- Record the error’s application ID, tenant/directory, timestamp, and correlation ID.
- Compare the configured ClientId with Application (client) ID in the intended app registration. Do not confuse it with the object ID or service-principal ID.
- Inspect the token authority/tenant in the app configuration and the tenant shown in the failed request. Check environment variables, deployment settings, and tenant-specific authority URLs.
- In the intended tenant, check whether the app registration exists. For a multitenant app, check whether its enterprise application/service principal has been created in that resource tenant and whether the app supports that tenant type.
- If the identifier belongs to a Microsoft first-party app or a third-party app, verify it from the app owner or vendor. Do not substitute an ID found in an unrelated forum post.
Root cause
The request’s client ID does not identify an application available in the tenant named by the request. A stale or incorrect client ID and an incorrect tenant authority are common configuration paths; a missing tenant-local service principal can matter for a multitenant application.
Resolution
Correct the client ID or tenant authority to match the intended registration. If a legitimate multitenant application has not yet been provisioned in the target tenant, follow the publisher’s onboarding and tenant-consent process after reviewing the requested permissions. Consent is an authorization decision, not a generic repair step.
Verification
- Retry token acquisition against the intended tenant and app ID.
- Confirm the sign-in log refers to the expected application and tenant.
- If token acquisition proceeds but returns a consent or permission error, diagnose that new code separately; do not treat it as the same failure.