azureblog.co.uk
← cd ~/errors
// entra id sign-in error · app registration and tokens

AADSTS50011

InvalidReplyTo

What it means

The reply URL in the request doesn't match any reply URL configured on the app.

How to fix it

Compare the redirect URI or ACS URL the app sends with the app registration or Enterprise App, including trailing slashes, http vs https and case.

How to investigate

  1. Compare what the app sends (client ID, redirect URI, scopes, tenant) with the app registration.
  2. Decode the token or request: the JWT and SAML decoders on this site show exactly what was sent.
  3. Check the app's credentials (secrets and certificates) and whether the service principal exists and is enabled in this tenant.
  4. Search the sign-in logs for the request ID or correlation ID from the troubleshooting details on the error page.

Tools that help

Error names and meanings follow Microsoft's error code reference. The fixes are this site's guidance.