// errors
Entra ID sign-in errors
61 common AADSTS error codes, grouped by cause, each with what it means, how to fix it and how to investigate. To search them all at once, use the AADSTS lookup.
Conditional Access and devices
- AADSTS50097DeviceAuthenticationRequiredDevice authentication is required.
- AADSTS50131ConditionalAccessFailedA Conditional Access failure such as bad device state, suspicious activity or a policy decision.
- AADSTS50155DeviceAuthenticationFailedDevice authentication failed for this user.
- AADSTS53000DeviceNotCompliantConditional Access requires a compliant device and this one isn't compliant.
- AADSTS53001DeviceNotDomainJoinedConditional Access requires a hybrid joined device.
- AADSTS53002ApplicationUsedIsNotAnApprovedAppThe app used isn't an approved app for Conditional Access.
- AADSTS53003BlockedByConditionalAccessAccess was blocked by a Conditional Access policy.
- AADSTS53004ProofUpBlockedDueToRiskThe user must complete MFA registration first, but registration is blocked because of risk.
- AADSTS530032BlockedByConditionalAccessOnSecurityPolicyA tenant security policy blocks the request.
MFA and registration
- AADSTS50072UserStrongAuthEnrollmentRequiredInterruptThe user needs to register for MFA.
- AADSTS50074UserStrongAuthClientAuthNRequiredInterruptStrong authentication was required and the user didn't pass the MFA challenge.
- AADSTS50076UserStrongAuthClientAuthNRequiredMFA is required because of an admin configuration such as Conditional Access.
- AADSTS50079UserStrongAuthEnrollmentRequiredThe user must register security info because of an admin configuration change.
- AADSTS50158External security challengeThe user was sent to an external challenge such as terms of use or third-party MFA.
- AADSTS90072PassThroughUserMfaErrorThe external account doesn't exist in the tenant, so it can't satisfy the tenant's MFA.
Accounts, passwords and sessions
- AADSTS16000InteractionRequiredThe account doesn't exist in this tenant and can't access the app.
- AADSTS50020UserUnauthorizedThe user's account isn't from this tenant and can't access the app.
- AADSTS50034UserAccountNotFoundThe account doesn't exist in the directory.
- AADSTS50053IdsLockedThe account is locked after too many failed sign-ins, or the sign-in came from an IP with malicious activity.
- AADSTS50055InvalidPasswordExpiredPasswordThe password has expired.
- AADSTS50056Invalid or null passwordNo password exists in the directory for this user.
- AADSTS50057UserDisabledThe user account is disabled.
- AADSTS50058UserInformationNotProvidedThere wasn't enough session information for single sign-on. The user usually isn't signed in.
- AADSTS50064CredentialAuthenticationErrorCredential validation on the username or password failed.
- AADSTS50089Flow token expiredThe sign-in took too long and the flow token expired.
- AADSTS50126InvalidUserNameOrPasswordThe username or password is wrong.
- AADSTS50128Invalid domain nameNo tenant-identifying information was found in the request.
- AADSTS50132SsoArtifactInvalidOrExpiredThe session isn't valid because of password expiry or a recent password change.
- AADSTS50133SsoArtifactRevokedThe session isn't valid because of password expiry or a recent password change.
- AADSTS50135PasswordChangeCompromisedPasswordA password change is required because of account risk.
- AADSTS50140KmsiInterruptThe 'Keep me signed in?' prompt.
- AADSTS50144InvalidPasswordExpiredOnPremPasswordThe user's Active Directory password has expired.
- AADSTS50173Grant expiredThe grant was revoked, often because the user changed or reset their password.
- AADSTS50199CmsiInterruptUser confirmation is needed because a system webview requested a token for a native app.
- AADSTS51004UserAccountNotInDirectoryThe user account doesn't exist in the directory.
- AADSTS81010DesktopSsoAuthTokenInvalidSeamless SSO failed because the Kerberos ticket is expired or invalid.
Consent and permissions
- AADSTS50105EntitlementGrantsNotFoundThe user isn't assigned to the app, and the app requires assignment.
- AADSTS65001DelegationDoesNotExistThe user or an admin hasn't consented to the app.
- AADSTS65004UserDeclinedConsentThe user declined consent.
- AADSTS90094AdminConsentRequiredAdmin consent is required.
- AADSTS650056Misconfigured applicationThe app is misconfigured: missing permissions, missing admin consent, or a mismatched client ID or certificate.
App registration and tokens
- AADSTS50011InvalidReplyToThe reply URL in the request doesn't match any reply URL configured on the app.
- AADSTS50107Federation realm not foundThe requested federation realm object doesn't exist.
- AADSTS50146MissingCustomSigningKeyThe app needs an app-specific signing key, which is missing, expired or not yet valid.
- AADSTS50196LoopDetectedThe app made too many of the same request in a short time.
- AADSTS54005Authorization code already redeemedThe OAuth2 authorization code was already used.
- AADSTS70000InvalidGrantAuthentication failed because the refresh token isn't valid.
- AADSTS70008ExpiredOrRevokedGrantThe refresh token expired due to inactivity.
- AADSTS70011InvalidScopeThe scope the app requested is invalid.
- AADSTS70043BadTokenDueToSignInFrequencyThe refresh token is invalid because of Conditional Access sign-in frequency.
- AADSTS500011InvalidResourceServicePrincipalNotFoundThe resource the app asked for wasn't found in the tenant.
- AADSTS500014InvalidResourceServicePrincipalDisabledThe resource's service principal is disabled.
- AADSTS700016UnauthorizedClient_DoesNotMatchRequestThe application wasn't found in the directory.
- AADSTS700027Client assertion signature failedThe client assertion failed signature validation.
- AADSTS700054ID token implicit grant not enabledresponse_type 'id_token' isn't enabled for the app.
- AADSTS700082ExpiredOrRevokedGrantInactiveTokenThe refresh token expired due to inactivity.
- AADSTS900144Missing required parameterThe request body is missing a required parameter.
- AADSTS900971No reply addressNo reply address was provided.
- AADSTS9002313InvalidRequestThe request is malformed or invalid.