AADSTS50076

Microsoft Entra ID Sign-in

AADSTS50076: multifactor authentication is required

Likely causes

  • A new or changed Conditional Access policy now requires MFA.
  • The user signed in from a new location or network.
  • The app uses legacy authentication that can't show an MFA prompt.
  • The user closed or missed the MFA prompt.

How to fix it

  1. Have the user sign in again and complete the MFA prompt. In many apps this is a normal step, not a failure.
  2. If the prompt never appears, update the app or switch to one that supports modern authentication. Old mail clients using basic authentication can’t do MFA.
  3. If the user’s MFA method doesn’t work (new phone, lost phone), an admin can require re-registration of MFA from the user’s authentication methods.
  4. Admins: check the sign-in logs Conditional Access tab to see which policy required MFA.
  5. Don’t exclude the user from the MFA policy as a fix. Get the app or method working instead.

Checked against: learn.microsoft.com, learn.microsoft.com

← All tools