AADSTS error lookup
Type an error code or a word from the message. Each entry gives Microsoft's error name, what it means and what to check.
· not listed? Check Microsoft's lookup for … ↗
-
AADSTS16000InteractionRequired
The account doesn't exist in this tenant and can't access the app.
Check: Add the user as a guest (B2B) or check they're signing in with the right account. Full guide →
-
AADSTS50011InvalidReplyTo
The reply URL in the request doesn't match any reply URL configured on the app.
Check: Compare the redirect URI or ACS URL the app sends with the app registration or Enterprise App, including trailing slashes, http vs https and case. Full guide →
-
AADSTS50020UserUnauthorized
The user's account isn't from this tenant and can't access the app.
Check: Invite the user as a guest, or point the app at the right tenant (or the common or organizations endpoint). Full guide →
-
AADSTS50034UserAccountNotFound
The account doesn't exist in the directory.
Check: Check for a typo in the username, or a missing or wrong UPN suffix. Full guide →
-
AADSTS50053IdsLocked
The account is locked after too many failed sign-ins, or the sign-in came from an IP with malicious activity.
Check: Wait for Smart Lockout to clear and investigate the source IPs in the sign-in logs for password spray. Full guide →
-
AADSTS50055InvalidPasswordExpiredPassword
The password has expired.
Check: Have the user reset it with SSPR, or reset it for them. Full guide →
-
AADSTS50056Invalid or null password
No password exists in the directory for this user.
Check: Common with federated or passwordless-only accounts. Check the authentication method the app is trying to use. Full guide →
-
AADSTS50057UserDisabled
The user account is disabled.
Check: Check whether that's intended (a leaver, or HR-driven provisioning) before re-enabling. Full guide →
-
AADSTS50058UserInformationNotProvided
There wasn't enough session information for single sign-on. The user usually isn't signed in.
Check: Usually harmless in silent sign-in attempts. Apps should fall back to an interactive sign-in. Full guide →
-
AADSTS50064CredentialAuthenticationError
Credential validation on the username or password failed.
Check: Check the credentials, and for hybrid users check the on-premises agent or federation service. Full guide →
-
AADSTS50072UserStrongAuthEnrollmentRequiredInterrupt
The user needs to register for MFA.
Check: Expected during first sign-in. Make sure registration isn't blocked by a Conditional Access policy on security info registration. Full guide →
-
AADSTS50074UserStrongAuthClientAuthNRequiredInterrupt
Strong authentication was required and the user didn't pass the MFA challenge.
Check: Often expected mid-flow. If it repeats, check the user's registered methods. Full guide →
-
AADSTS50076UserStrongAuthClientAuthNRequired
MFA is required because of an admin configuration such as Conditional Access.
Check: Expected when the user hasn't done MFA yet. Non-interactive clients must do an interactive sign-in. Full guide →
-
AADSTS50079UserStrongAuthEnrollmentRequired
The user must register security info because of an admin configuration change.
Check: Guide the user through registration, or issue a Temporary Access Pass. Full guide →
-
AADSTS50089Flow token expired
The sign-in took too long and the flow token expired.
Check: Ask the user to sign in again without leaving the page open. Full guide →
-
AADSTS50097DeviceAuthenticationRequired
Device authentication is required.
Check: Check the device's registration state (dsregcmd /status on Windows) and its Primary Refresh Token. Full guide →
-
AADSTS50105EntitlementGrantsNotFound
The user isn't assigned to the app, and the app requires assignment.
Check: Assign the user or a group they're in on the Enterprise App's Users and groups blade. Full guide →
-
AADSTS50107Federation realm not found
The requested federation realm object doesn't exist.
Check: Check the domain's federation configuration, or the issuer the SAML app sends. Full guide →
-
AADSTS50126InvalidUserNameOrPassword
The username or password is wrong.
Check: Some are normal user error. Many from one IP across many users suggests password spray. Full guide →
-
AADSTS50128Invalid domain name
No tenant-identifying information was found in the request.
Check: Check the username's domain is verified in a tenant, and the app uses the right authority URL. Full guide →
-
AADSTS50131ConditionalAccessFailed
A Conditional Access failure such as bad device state, suspicious activity or a policy decision.
Check: Open the sign-in log entry's Conditional Access tab to see which policy failed and why. Full guide →
-
AADSTS50132SsoArtifactInvalidOrExpired
The session isn't valid because of password expiry or a recent password change.
Check: Sign in again with the new password. Full guide →
-
AADSTS50133SsoArtifactRevoked
The session isn't valid because of password expiry or a recent password change.
Check: Sign in again. Sessions may also have been revoked by an admin. Full guide →
-
AADSTS50135PasswordChangeCompromisedPassword
A password change is required because of account risk.
Check: Review the risk in ID Protection and have the user change their password securely. Full guide →
-
AADSTS50140KmsiInterrupt
The 'Keep me signed in?' prompt.
Check: Expected and harmless. It appears in logs as an interrupt, not a failure. Full guide →
-
AADSTS50144InvalidPasswordExpiredOnPremPassword
The user's Active Directory password has expired.
Check: Reset it on-premises, or enable password writeback so SSPR can reset it. Full guide →
-
AADSTS50146MissingCustomSigningKey
The app needs an app-specific signing key, which is missing, expired or not yet valid.
Check: Check the SAML signing certificate on the Enterprise App and its expiry. Full guide →
-
AADSTS50155DeviceAuthenticationFailed
Device authentication failed for this user.
Check: Re-register the device or check that the device object is enabled in Entra. Full guide →
-
AADSTS50158External security challenge
The user was sent to an external challenge such as terms of use or third-party MFA.
Check: Expected in the flow. On its own it doesn't mean the sign-in failed. Full guide →
-
AADSTS50173Grant expired
The grant was revoked, often because the user changed or reset their password.
Check: Sign in again to get a fresh token. Full guide →
-
AADSTS50196LoopDetected
The app made too many of the same request in a short time.
Check: A bug in the app's token handling. Check that it caches tokens. Full guide →
-
AADSTS50199CmsiInterrupt
User confirmation is needed because a system webview requested a token for a native app.
Check: Expected anti-spoofing prompt. The user should confirm. Full guide →
-
AADSTS51004UserAccountNotInDirectory
The user account doesn't exist in the directory.
Check: Check the username and tenant. Full guide →
-
AADSTS53000DeviceNotCompliant
Conditional Access requires a compliant device and this one isn't compliant.
Check: Check the device in Intune's compliance report, and that the user is signing in from a managed, registered device. Full guide →
-
AADSTS53001DeviceNotDomainJoined
Conditional Access requires a hybrid joined device.
Check: Check the device's join state with dsregcmd /status. Full guide →
-
AADSTS53002ApplicationUsedIsNotAnApprovedApp
The app used isn't an approved app for Conditional Access.
Check: Use an approved client app, such as Outlook mobile instead of a native mail app. Full guide →
-
AADSTS53003BlockedByConditionalAccess
Access was blocked by a Conditional Access policy.
Check: Open the sign-in log entry's Conditional Access tab to find the blocking policy, then use What If to test. Full guide →
-
AADSTS53004ProofUpBlockedDueToRisk
The user must complete MFA registration first, but registration is blocked because of risk.
Check: Investigate the user's risk, then issue a Temporary Access Pass if appropriate. Full guide →
-
AADSTS54005Authorization code already redeemed
The OAuth2 authorization code was already used.
Check: An app bug. Each code can be redeemed once; use the refresh token instead. Full guide →
-
AADSTS65001DelegationDoesNotExist
The user or an admin hasn't consented to the app.
Check: Grant admin consent, or let the user consent if your consent settings allow it. Full guide →
-
AADSTS65004UserDeclinedConsent
The user declined consent.
Check: Expected if the user chose to. If they need the app, use the admin consent workflow. Full guide →
-
AADSTS70000InvalidGrant
Authentication failed because the refresh token isn't valid.
Check: Sign in again. Full guide →
-
AADSTS70008ExpiredOrRevokedGrant
The refresh token expired due to inactivity.
Check: Sign in again. This is expected after long inactivity. Full guide →
-
AADSTS70011InvalidScope
The scope the app requested is invalid.
Check: Check the scope format in the app, such as https://graph.microsoft.com/.default for client credentials. Full guide →
-
AADSTS70043BadTokenDueToSignInFrequency
The refresh token is invalid because of Conditional Access sign-in frequency.
Check: Expected when the sign-in frequency is reached. The user signs in again. Full guide →
-
AADSTS75005Saml2MessageInvalid
Entra doesn't support the SAML request the app sent.
Check: Decode the request (try the SAML decoder) and check the binding and format. Full guide →
-
AADSTS75011NoMatchedAuthnContextInOutputClaims
The authentication method used doesn't match the one the app requested.
Check: The app sent a RequestedAuthnContext with an exact comparison. Ask the vendor to remove it or use minimum. Full guide →
-
AADSTS81010DesktopSsoAuthTokenInvalid
Seamless SSO failed because the Kerberos ticket is expired or invalid.
Check: Check the AZUREADSSOACC computer account and roll its Kerberos decryption key if it's overdue. Full guide →
-
AADSTS90072PassThroughUserMfaError
The external account doesn't exist in the tenant, so it can't satisfy the tenant's MFA.
Check: Invite the user as a guest, or check cross-tenant trust settings for MFA. Full guide →
-
AADSTS90094AdminConsentRequired
Admin consent is required.
Check: An admin must grant consent, or the user can request it via the admin consent workflow. Full guide →
-
AADSTS500011InvalidResourceServicePrincipalNotFound
The resource the app asked for wasn't found in the tenant.
Check: Check the resource or scope URI, and that the resource app is installed and consented in this tenant. Full guide →
-
AADSTS500014InvalidResourceServicePrincipalDisabled
The resource's service principal is disabled.
Check: Check whether the Enterprise App was disabled on purpose. A lapsed subscription can also disable it. Full guide →
-
AADSTS530032BlockedByConditionalAccessOnSecurityPolicy
A tenant security policy blocks the request.
Check: Check Conditional Access and security defaults in the sign-in log entry. Full guide →
-
AADSTS650056Misconfigured application
The app is misconfigured: missing permissions, missing admin consent, or a mismatched client ID or certificate.
Check: Review the app registration's API permissions and consent status. Full guide →
-
AADSTS700016UnauthorizedClient_DoesNotMatchRequest
The application wasn't found in the directory.
Check: Check the client ID and that the app is signing in to the right tenant. Full guide →
-
AADSTS700027Client assertion signature failed
The client assertion failed signature validation.
Check: The certificate used to sign doesn't match one uploaded to the app registration, or it has expired. Full guide →
-
AADSTS700054ID token implicit grant not enabled
response_type 'id_token' isn't enabled for the app.
Check: Enable ID tokens for implicit grant on the app registration, or better, move to the authorization code flow. Full guide →
-
AADSTS700082ExpiredOrRevokedGrantInactiveToken
The refresh token expired due to inactivity.
Check: Expected. The user signs in again. Full guide →
-
AADSTS900144Missing required parameter
The request body is missing a required parameter.
Check: A developer error. Check the request against the OAuth or OpenID Connect spec. Full guide →
-
AADSTS900971No reply address
No reply address was provided.
Check: Add a redirect URI to the request and the app registration. Full guide →
-
AADSTS9002313InvalidRequest
The request is malformed or invalid.
Check: Capture the request (browser dev tools or Fiddler) and check its format. Full guide →
No match here. Try Microsoft's lookup link above.
Error names and meanings follow Microsoft's error code reference.