[Important Security Notice] Fake Qfinder Pro Websites Detected. Learn more >

Why do login attempts by Microsoft Entra ID SSO external users fail after updating to QTS 5.2.8 (special build, Oct 27) or later?


Last modified date: 2026-02-09

Applicable Products

  • QTS 5.2.8 (Special Build, Oct. 27, 2025)  and later
  • QuTS hero h5.2.8 (Special Build, Oct. 27, 2025)  and later

Root Cause

Starting with QTS and QuTS hero 5.2.8, NAS devices require authentication tokens issued by Microsoft Entra ID to include the User Principal Name (UPN) claim during login.

If the UPN claim is not enabled for an external user account, the NAS device cannot identify the user, and the login attempt is rejected.


Solution

To allow external users to log in, enable the UPN claim in the Microsoft Entra ID (Azure AD) portal.

  1. Sign in to Microsoft Azure.
  2. Click All Services.
  3. Navigate to Hybrid + multicloud.
  4. Click Microsoft Entra ID.
  5. On the side menu, go to Manage > App registrations > All applications.
  6. Click your registered application.
  7. On the side menu, go to Manage > Token configuration.
  8. Click + Add optional claim
    The Add optional claim window appears.
  9. Select the token type as ID.
    The Claim setting appear.
  10. Locate and select upn.
  11. Click Add.
    Note
    Microsoft Entra ID may display a notification stating that some claims (such as family_name, given_name, and upn) require OpenID Connect scopes or Microsoft Graph permissions to be included in the authentication token.
    This notification appears because Microsoft Entra ID must grant the application permission to access user profile information before these claims can be issued in tokens. When this notification appears, enable Select Turn on the Microsoft Graph profile permission, and click Add.
  12. In the Optional claims page, locate the upn claim.
  13. Click and then click Edit.
    The Edit UPN (ID token) window appears. 
  14. Under Externally authenticated, enable the switch to Yes.
  15. Click Save.

Allow up to one minute for synchronization to complete. After the synchronization process finishes, Microsoft Entra ID users should be able to authenticate successfully to the NAS using SSO.


Further Reading

Was this article helpful?

Thank you for your feedback.

Please tell us how this article can be improved:

If you want to provide additional feedback, please include it below.

Choose specification

      Show more Less
      Choose Your Country or Region
      open menu
      back to top