← cd ~/errors
// entra id sign-in error · mfa and registration
AADSTS50076
UserStrongAuthClientAuthNRequired
What it means
MFA is required because of an admin configuration such as Conditional Access.
How to fix it
Expected when the user hasn't done MFA yet. Non-interactive clients must do an interactive sign-in.
How to investigate
- Open the sign-in log entry and check the Authentication details tab to see which methods were offered and which step failed.
- Check the user's registered methods under their Authentication methods blade.
- Check which Conditional Access policy or authentication strength asked for MFA.
- Search the sign-in logs for the request ID or correlation ID from the troubleshooting details on the error page.
Guides on this site
Tools that help
Error names and meanings follow Microsoft's error code reference. The fixes are this site's guidance.