azureblog.co.uk
← cd ~/tools
// tools/aadsts

AADSTS error lookup

Type an error code or a word from the message. Each entry gives Microsoft's error name, what it means and what to check.

· not listed? Check Microsoft's lookup for … ↗

  1. AADSTS16000InteractionRequired

    The account doesn't exist in this tenant and can't access the app.

    Check: Add the user as a guest (B2B) or check they're signing in with the right account. Full guide →

  2. AADSTS50011InvalidReplyTo

    The reply URL in the request doesn't match any reply URL configured on the app.

    Check: Compare the redirect URI or ACS URL the app sends with the app registration or Enterprise App, including trailing slashes, http vs https and case. Full guide →

  3. AADSTS50020UserUnauthorized

    The user's account isn't from this tenant and can't access the app.

    Check: Invite the user as a guest, or point the app at the right tenant (or the common or organizations endpoint). Full guide →

  4. AADSTS50034UserAccountNotFound

    The account doesn't exist in the directory.

    Check: Check for a typo in the username, or a missing or wrong UPN suffix. Full guide →

  5. AADSTS50053IdsLocked

    The account is locked after too many failed sign-ins, or the sign-in came from an IP with malicious activity.

    Check: Wait for Smart Lockout to clear and investigate the source IPs in the sign-in logs for password spray. Full guide →

  6. AADSTS50055InvalidPasswordExpiredPassword

    The password has expired.

    Check: Have the user reset it with SSPR, or reset it for them. Full guide →

  7. AADSTS50056Invalid or null password

    No password exists in the directory for this user.

    Check: Common with federated or passwordless-only accounts. Check the authentication method the app is trying to use. Full guide →

  8. AADSTS50057UserDisabled

    The user account is disabled.

    Check: Check whether that's intended (a leaver, or HR-driven provisioning) before re-enabling. Full guide →

  9. AADSTS50058UserInformationNotProvided

    There wasn't enough session information for single sign-on. The user usually isn't signed in.

    Check: Usually harmless in silent sign-in attempts. Apps should fall back to an interactive sign-in. Full guide →

  10. AADSTS50064CredentialAuthenticationError

    Credential validation on the username or password failed.

    Check: Check the credentials, and for hybrid users check the on-premises agent or federation service. Full guide →

  11. AADSTS50072UserStrongAuthEnrollmentRequiredInterrupt

    The user needs to register for MFA.

    Check: Expected during first sign-in. Make sure registration isn't blocked by a Conditional Access policy on security info registration. Full guide →

  12. AADSTS50074UserStrongAuthClientAuthNRequiredInterrupt

    Strong authentication was required and the user didn't pass the MFA challenge.

    Check: Often expected mid-flow. If it repeats, check the user's registered methods. Full guide →

  13. AADSTS50076UserStrongAuthClientAuthNRequired

    MFA is required because of an admin configuration such as Conditional Access.

    Check: Expected when the user hasn't done MFA yet. Non-interactive clients must do an interactive sign-in. Full guide →

  14. AADSTS50079UserStrongAuthEnrollmentRequired

    The user must register security info because of an admin configuration change.

    Check: Guide the user through registration, or issue a Temporary Access Pass. Full guide →

  15. AADSTS50089Flow token expired

    The sign-in took too long and the flow token expired.

    Check: Ask the user to sign in again without leaving the page open. Full guide →

  16. AADSTS50097DeviceAuthenticationRequired

    Device authentication is required.

    Check: Check the device's registration state (dsregcmd /status on Windows) and its Primary Refresh Token. Full guide →

  17. AADSTS50105EntitlementGrantsNotFound

    The user isn't assigned to the app, and the app requires assignment.

    Check: Assign the user or a group they're in on the Enterprise App's Users and groups blade. Full guide →

  18. AADSTS50107Federation realm not found

    The requested federation realm object doesn't exist.

    Check: Check the domain's federation configuration, or the issuer the SAML app sends. Full guide →

  19. AADSTS50126InvalidUserNameOrPassword

    The username or password is wrong.

    Check: Some are normal user error. Many from one IP across many users suggests password spray. Full guide →

  20. AADSTS50128Invalid domain name

    No tenant-identifying information was found in the request.

    Check: Check the username's domain is verified in a tenant, and the app uses the right authority URL. Full guide →

  21. AADSTS50131ConditionalAccessFailed

    A Conditional Access failure such as bad device state, suspicious activity or a policy decision.

    Check: Open the sign-in log entry's Conditional Access tab to see which policy failed and why. Full guide →

  22. AADSTS50132SsoArtifactInvalidOrExpired

    The session isn't valid because of password expiry or a recent password change.

    Check: Sign in again with the new password. Full guide →

  23. AADSTS50133SsoArtifactRevoked

    The session isn't valid because of password expiry or a recent password change.

    Check: Sign in again. Sessions may also have been revoked by an admin. Full guide →

  24. AADSTS50135PasswordChangeCompromisedPassword

    A password change is required because of account risk.

    Check: Review the risk in ID Protection and have the user change their password securely. Full guide →

  25. AADSTS50140KmsiInterrupt

    The 'Keep me signed in?' prompt.

    Check: Expected and harmless. It appears in logs as an interrupt, not a failure. Full guide →

  26. AADSTS50144InvalidPasswordExpiredOnPremPassword

    The user's Active Directory password has expired.

    Check: Reset it on-premises, or enable password writeback so SSPR can reset it. Full guide →

  27. AADSTS50146MissingCustomSigningKey

    The app needs an app-specific signing key, which is missing, expired or not yet valid.

    Check: Check the SAML signing certificate on the Enterprise App and its expiry. Full guide →

  28. AADSTS50155DeviceAuthenticationFailed

    Device authentication failed for this user.

    Check: Re-register the device or check that the device object is enabled in Entra. Full guide →

  29. AADSTS50158External security challenge

    The user was sent to an external challenge such as terms of use or third-party MFA.

    Check: Expected in the flow. On its own it doesn't mean the sign-in failed. Full guide →

  30. AADSTS50173Grant expired

    The grant was revoked, often because the user changed or reset their password.

    Check: Sign in again to get a fresh token. Full guide →

  31. AADSTS50196LoopDetected

    The app made too many of the same request in a short time.

    Check: A bug in the app's token handling. Check that it caches tokens. Full guide →

  32. AADSTS50199CmsiInterrupt

    User confirmation is needed because a system webview requested a token for a native app.

    Check: Expected anti-spoofing prompt. The user should confirm. Full guide →

  33. AADSTS51004UserAccountNotInDirectory

    The user account doesn't exist in the directory.

    Check: Check the username and tenant. Full guide →

  34. AADSTS53000DeviceNotCompliant

    Conditional Access requires a compliant device and this one isn't compliant.

    Check: Check the device in Intune's compliance report, and that the user is signing in from a managed, registered device. Full guide →

  35. AADSTS53001DeviceNotDomainJoined

    Conditional Access requires a hybrid joined device.

    Check: Check the device's join state with dsregcmd /status. Full guide →

  36. AADSTS53002ApplicationUsedIsNotAnApprovedApp

    The app used isn't an approved app for Conditional Access.

    Check: Use an approved client app, such as Outlook mobile instead of a native mail app. Full guide →

  37. AADSTS53003BlockedByConditionalAccess

    Access was blocked by a Conditional Access policy.

    Check: Open the sign-in log entry's Conditional Access tab to find the blocking policy, then use What If to test. Full guide →

  38. AADSTS53004ProofUpBlockedDueToRisk

    The user must complete MFA registration first, but registration is blocked because of risk.

    Check: Investigate the user's risk, then issue a Temporary Access Pass if appropriate. Full guide →

  39. AADSTS54005Authorization code already redeemed

    The OAuth2 authorization code was already used.

    Check: An app bug. Each code can be redeemed once; use the refresh token instead. Full guide →

  40. AADSTS65001DelegationDoesNotExist

    The user or an admin hasn't consented to the app.

    Check: Grant admin consent, or let the user consent if your consent settings allow it. Full guide →

  41. AADSTS65004UserDeclinedConsent

    The user declined consent.

    Check: Expected if the user chose to. If they need the app, use the admin consent workflow. Full guide →

  42. AADSTS70000InvalidGrant

    Authentication failed because the refresh token isn't valid.

    Check: Sign in again. Full guide →

  43. AADSTS70008ExpiredOrRevokedGrant

    The refresh token expired due to inactivity.

    Check: Sign in again. This is expected after long inactivity. Full guide →

  44. AADSTS70011InvalidScope

    The scope the app requested is invalid.

    Check: Check the scope format in the app, such as https://graph.microsoft.com/.default for client credentials. Full guide →

  45. AADSTS70043BadTokenDueToSignInFrequency

    The refresh token is invalid because of Conditional Access sign-in frequency.

    Check: Expected when the sign-in frequency is reached. The user signs in again. Full guide →

  46. AADSTS75005Saml2MessageInvalid

    Entra doesn't support the SAML request the app sent.

    Check: Decode the request (try the SAML decoder) and check the binding and format. Full guide →

  47. AADSTS75011NoMatchedAuthnContextInOutputClaims

    The authentication method used doesn't match the one the app requested.

    Check: The app sent a RequestedAuthnContext with an exact comparison. Ask the vendor to remove it or use minimum. Full guide →

  48. AADSTS81010DesktopSsoAuthTokenInvalid

    Seamless SSO failed because the Kerberos ticket is expired or invalid.

    Check: Check the AZUREADSSOACC computer account and roll its Kerberos decryption key if it's overdue. Full guide →

  49. AADSTS90072PassThroughUserMfaError

    The external account doesn't exist in the tenant, so it can't satisfy the tenant's MFA.

    Check: Invite the user as a guest, or check cross-tenant trust settings for MFA. Full guide →

  50. AADSTS90094AdminConsentRequired

    Admin consent is required.

    Check: An admin must grant consent, or the user can request it via the admin consent workflow. Full guide →

  51. AADSTS500011InvalidResourceServicePrincipalNotFound

    The resource the app asked for wasn't found in the tenant.

    Check: Check the resource or scope URI, and that the resource app is installed and consented in this tenant. Full guide →

  52. AADSTS500014InvalidResourceServicePrincipalDisabled

    The resource's service principal is disabled.

    Check: Check whether the Enterprise App was disabled on purpose. A lapsed subscription can also disable it. Full guide →

  53. AADSTS530032BlockedByConditionalAccessOnSecurityPolicy

    A tenant security policy blocks the request.

    Check: Check Conditional Access and security defaults in the sign-in log entry. Full guide →

  54. AADSTS650056Misconfigured application

    The app is misconfigured: missing permissions, missing admin consent, or a mismatched client ID or certificate.

    Check: Review the app registration's API permissions and consent status. Full guide →

  55. AADSTS700016UnauthorizedClient_DoesNotMatchRequest

    The application wasn't found in the directory.

    Check: Check the client ID and that the app is signing in to the right tenant. Full guide →

  56. AADSTS700027Client assertion signature failed

    The client assertion failed signature validation.

    Check: The certificate used to sign doesn't match one uploaded to the app registration, or it has expired. Full guide →

  57. AADSTS700054ID token implicit grant not enabled

    response_type 'id_token' isn't enabled for the app.

    Check: Enable ID tokens for implicit grant on the app registration, or better, move to the authorization code flow. Full guide →

  58. AADSTS700082ExpiredOrRevokedGrantInactiveToken

    The refresh token expired due to inactivity.

    Check: Expected. The user signs in again. Full guide →

  59. AADSTS900144Missing required parameter

    The request body is missing a required parameter.

    Check: A developer error. Check the request against the OAuth or OpenID Connect spec. Full guide →

  60. AADSTS900971No reply address

    No reply address was provided.

    Check: Add a redirect URI to the request and the app registration. Full guide →

  61. AADSTS9002313InvalidRequest

    The request is malformed or invalid.

    Check: Capture the request (browser dev tools or Fiddler) and check its format. Full guide →

Error names and meanings follow Microsoft's error code reference.