Unable to create an Outlook profile after a migration with Event 1098 in AAD log

Applies to: Outlook 2016Outlook 2019

Symptoms


When you try to create a Microsoft Outlook profile after a domain migration, you receive an error message that indicates you "cannot start Outlook" or "something went wrong." You also receive a sign-in prompt.

Additionally, you may see the Event 1098 in Azure Active Directory (AAD) Operational log that resembles the following:


To find the AAD Operational log in Event Viewer, locate Applications and Services Logs > Microsoft > Windows > AAD > Operational

Azure Active Directory location in Event Viewer

Cause


There are multiple scenarios that can result in a change to a user security identifier (SID), for example, migrating the user to a new domain. However, the user profile is not changed, and data files that have the old SID are now cached in an old profile. In this case, you may have an Office connection problem or authentication loops which results in this error.

Resolution


To resolve this issue, follow these steps: 

  1. Delete all files from the Accounts folder at the following: location: 

    %LOCALAPPDATA%\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\TokenBroker\Accounts 

    Note Copy and paste the above location in the Windows Search box to find the folder.
  2. Restart and re-create an Outlook profile.