azureblog.co.uk
← cd ~/errors
// entra id sign-in error · saml single sign-on

AADSTS75011

NoMatchedAuthnContextInOutputClaims

What it means

The authentication method used doesn't match the one the app requested.

How to fix it

The app sent a RequestedAuthnContext with an exact comparison. Ask the vendor to remove it or use minimum.

How to investigate

  1. Capture the SAMLRequest from the browser and decode it with the SAML decoder.
  2. Compare the Identifier, Reply URL and requested authentication context with the Enterprise App's SAML settings.
  3. Check the signing certificate is active and matches what the app expects.
  4. Search the sign-in logs for the request ID or correlation ID from the troubleshooting details on the error page.

Guides on this site

Tools that help

Error names and meanings follow Microsoft's error code reference. The fixes are this site's guidance.