web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

No record found.

News and Announcements icon
Community site session details

Community site session details

Session Id :
FastTrack for Dynamics 365 forum
Answered

Document Routing Agent – Guest User Unable to Authenticate ("Agent version check failed")

(0) ShareShare
ReportReport
Posted on by 677

Hi,

 

We are seeing an authentication failure in the Document Routing Agent (DRA) that is specific to guest user accounts, and would like the community's input on the underlying cause.

DRA version: 7.0.7996.81
Environment: D365 F&O Sandbox (QA)

 

Observed behavior:

- Signing into the DRA with a native tenant account succeeds with no errors.
- Signing into the DRA with a guest account (from a partner/external tenant) fails with: "Agent could not connect to Microsoft Dynamics 365 for Finance and Operations. Agent version check failed."
- This is the same DRA build in both cases, on the same environment, tested within the same session.
- The guest account holds the System Administrator role in this D365 F&O environment, ruling out a security role assignment gap (e.g. "Document routing client" role, which System Administrator encompasses).
- Standard D365 F&O browser access via this guest account works normally with no sign-in issues.

Our working theory is that the "version check failed" message is masking an underlying authentication/token failure specific to guest (B2B) accounts - potentially related to Conditional Access policy scoping, guest consent, or token exchange behaviour that differs between guest and native accounts during the DRA's Entra ID sign-in flow, rather than an actual DRA version mismatch.

 

Has anyone else run into this? Specifically interested in:
1. Whether the DRA's Entra ID authentication flow is known to behave differently for guest vs. member accounts, and what token/consent requirements apply specifically to guest sign-in.
2. Whether "Agent version check failed" can be triggered by an authentication failure rather than an actual agent/environment version mismatch, and how to distinguish the two.
3. Any recommended configuration (e.g. Conditional Access exclusions, guest consent settings) to support guest account sign-in to the DRA.

 

Thanks in advance.

  • Verified answer
    Navneeth Nagrajan Profile Picture
    2,699 Super User 2026 Season 2 on at

    Hi @Rizwan Ahmed - MCT,
     

    1. Whether the DRA's Entra ID authentication flow is known to behave differently for guest vs. member accounts, and what token/consent requirements apply specifically to guest sign-in.
    - D365 FO in general supports Entra ID tokens for session authentication, and token acquisition often expects the home tenant as the primary token issuer. In case of guest accounts, it indicates the guest account introduces delegation and consent complexities, which are aggravated by conditional access policies. The official documentation states that an Entra ID account is required to configure Document routing agent and must share the same domain as the Azure tenant. At the same time, the individual installing the document routing agent and configuring the printers should have Document routing client security role. The token handling model is inconsistent with guest accounts. 
    2. Whether "Agent version check failed" can be triggered by an authentication failure rather than an actual agent/environment version mismatch, and how to distinguish the two.
    Yes, the error message of agent version check failed is misleading in certain scenarios. Token issues can result in an inability to validate agent state against the environment. Multi-factor authentication should be disabled for this guest account (i.e. service account) that is used to connect the Document routing agent to D365 FO. Recommendation is to a service account with Document routing client security role/System admin role in D365 Fo. Also, would recommend to run the document routing agent as a windows service instead of running it on a DRA client 

    3. Any recommended configuration (e.g. Conditional Access exclusions, guest consent settings) to support guest account sign-in to the DRA.
    Temporarily exempt the guest account from device compliance or MFA for the affected accounts. Guest users may need explicit admin consent or proper app configuration for DRA endpoints in the home tenant. Microsoft recommends creating internal accounts in Entra ID for those users (with relevant roles) rather than relying on B2B, aligning with guidance for other unsupported guest scenarios. 

    References:
    https://learn.microsoft.com/en-us/dynamics365/fin-ops-core/dev-itpro/analytics/install-document-routing-agent

     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Women in Power Builds Momentum

Expanding mentorship, skilling, and AI innovation

Congratulations to the July Top 10 Community Leaders

These are the community rock stars!

Leaderboard > FastTrack for Dynamics 365

#1
Aayush Tiwari Profile Picture

Aayush Tiwari 16

#2
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 6 Super User 2026 Season 2

#3
Anthony Blake Profile Picture

Anthony Blake 2 Super User 2026 Season 2

Last 30 days Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans