azureblog.co.uk
← cd ~/errors
// entra id sign-in error · saml single sign-on

AADSTS75005

Saml2MessageInvalid

What it means

Entra doesn't support the SAML request the app sent.

How to fix it

Decode the request (try the SAML decoder) and check the binding and format.

How to investigate

  1. Capture the SAMLRequest from the browser and decode it with the SAML decoder.
  2. Compare the Identifier, Reply URL and requested authentication context with the Enterprise App's SAML settings.
  3. Check the signing certificate is active and matches what the app expects.
  4. Search the sign-in logs for the request ID or correlation ID from the troubleshooting details on the error page.

Guides on this site

Tools that help

Error names and meanings follow Microsoft's error code reference. The fixes are this site's guidance.