群组含禁用用户时,空教师/学生段创建课堂笔记本失败问题
The Problem
When creating a OneNote Class Notebook via the API for an Azure AD group that contains a user with "Block sign-in" enabled (in Azure Portal), you'll get a 30109 NotFound error pointing to the disabled user—even if you didn't add that user to the teachers or students arrays in your request body.
How to Reproduce the Issue
- Use a Microsoft Education demo tenant
- Create a new user with a valid Office 365 license and usage location, then set Block sign-in to
Truein the Azure Portal - Create an Azure AD group and add the disabled user as a member (can include other enabled users too—doesn't affect the result)
- Call the OneNote API to create a class notebook:
Request body:POST https://www.onenote.com/api/v1.0/myOrganization/groups/{groupId}/notes/classNotebooks/?omkt=de-de{ "name": "Class notebook of my group", "teachers": [], "students": [], "studentSections": [], "hasTeacherOnlySectionGroup": true }
Error Message Received
System.Net.Http.HttpRequestException: Response status code does not indicate success: 404 (NotFound).
{
"error": {
"code": "30109",
"message": "The following users are invalid: Message: Der angegebene Benutzer disabled.user@mydomain.com wurde nicht gefunden., ServerErrorCode: -2146232832, ServerErrorTypeName: Microsoft.SharePoint.SPException",
"@api.url": "https://aka.ms/onenote-errors#C30109"
}
}
Why This Happens
The OneNote Class Notebook API automatically scans all members of the target group during the creation process to validate their status, even if you don't explicitly list them in your request. When a user has sign-in blocked, SharePoint's backend marks them as unavailable, which triggers the "user not found" validation error.
Solutions
- Temporarily remove the disabled user from the group:
- Remove the blocked user from the Azure AD group before calling the API
- After successfully creating the class notebook, you can add the disabled user back to the group if needed
- Use a dedicated group with only enabled users:
Create a separate group that only includes active (non-blocked) users to use for the notebook creation. Once the notebook is set up, you can add the disabled user to the original group later. - Temporarily enable the user:
If the user needs to stay in the group, turn off the "Block sign-in" setting temporarily, create the notebook, then re-enable the block.
Note
Right now, there's no API parameter to skip validation of group members, so these workarounds are the most straightforward way to get past this issue.
内容的提问来源于stack exchange,提问作者Oliver

