Error CAA50021 during device registration in Entra ID

During my tests, I keep changing configurations in Entra ID and Intune. This was also the case a few days ago. I deleted one of my “Entra registered” devices in Entra ID for a test.

In Windows, Microsoft applications (like Edge, Teams, and others) first reported my organization deleted the device.

Your organization has deleted this device.

Screenshot

The device is still connected to Entra ID. I disconnect the device via Windows Settings > Accounts > Access work or school. As a result, applications no longer show the message.

Verbindung mit Entra ID lösen
Disconnect the device from Entra ID

I want to add the account again via Windows Settings > Email & Accounts to re-register my PC in Entra ID.

PC im Tenant neu registrieren
Re-register the PC in Entra ID

Alternatively, Edge, Teams, and other Microsoft applications show the familiar message an organization could manage the device.

Screenshot

My re-registration of the PC takes a very long time and ends with an error / time-out.

CAA50021 – Number of retry attempts exceeds expectation

Fehler CAA50021 während der Neuregistrierung
Error CAA50021 during re-registration

A check in Entra ID shows permanent errors for the account and “Device Registration Service”.

Sign-in Logs in Entra ID
Sign-in logs in Entra ID

The search for CAA50021 error results in a lot of suggestions for a solution. None of them helped in my case.

With the addition for “Device Registration Service” I found the following information, noted in Microsoft’s FAQs for Entra ID devices:

What are the MS-Organization-Access certificates present on our Windows 10/11 devices?
The MS-Organization-Access certificates are issued by the Microsoft Entra Device Registration Service during the device registration process. These certificates are issued to all join types supported on Windows – Microsoft Entra joined, Microsoft Entra hybrid joined and Microsoft Entra registered devices. Once issued, they’re used as part of the authentication process from the device to request a Primary Refresh Token (PRT). For Microsoft Entra joined and Microsoft Entra hybrid joined devices, this certificate is present in Local Computer\Personal\Certificates whereas for Microsoft Entra registered devices, certificate is present in Current User\Personal\Certificates. All MS-Organization-Access certificates have a default lifetime of 10 years. These certificates are deleted from the corresponding certificate store when the device is unregistered from Microsoft Entra ID. Any inadvertent deletion of this certificate leads to authentication failures for the user, and requiring re-registration of the device in such cases.

My device has been deleted. I can find the deleted device ID in the Entra ID audit log.

Audit Log in Entra ID
Audit log in Entra ID

I check the local certificates for my account. The certificate from my deleted and disconnected device is still available.

Certificate for my disconnected PC
Certificate for my disconnected PC

I delete the certificate and try to register my PC again.
It only takes a few seconds and my PC is successfully registered.

Neuregistrierung abgeschlossen
Re-registration completed

My PC has been re-registered in Entra ID.

Device Object in Entra ID
Device object in Entra ID

The certificate has been recreated on my PC.

Zertifikat für registrierten PC
Certificate for registered PC

Conclusion:
If you delete a device in Entra ID and want to re-register it, make sure that the old device certificate is no longer available on your PC.

Share
Avatar photo

Tobias Asböck

Tobias is a Senior System Engineer with around ten years of professional experience with Microsoft 365 products such as SharePoint Online, OneDrive for Business, Teams Collaboration, Entra ID, Information Protection, Universal Print, and Microsoft 365 Licensing. He also has 15+ years of experience planning, administering, and operating SharePoint Server environments. Tobias is a PowerShell Scripter with certifications for Microsoft 365 products. In his spare time, Tobias is busy with updates in the Microsoft 365 world or on the road with his road bike and other sports activities. If you have additional questions, please contact me via LinkedIn or [email protected].

Leave a Reply

Your email address will not be published. Required fields are marked *