← cd ~/errors
// entra id sign-in error · accounts, passwords and sessions
AADSTS81010
DesktopSsoAuthTokenInvalid
What it means
Seamless SSO failed because the Kerberos ticket is expired or invalid.
How to fix it
Check the AZUREADSSOACC computer account and roll its Kerberos decryption key if it's overdue.
How to investigate
- Confirm which account the user actually signed in with. A personal account or the wrong tenant causes many of these.
- Check the user object: enabled, licensed, in the right tenant, and with no recent password change or reset.
- Look at the sign-in logs over a few days for a pattern, such as repeated failures from one IP address.
- Search the sign-in logs for the request ID or correlation ID from the troubleshooting details on the error page.
Tools that help
Error names and meanings follow Microsoft's error code reference. The fixes are this site's guidance.