AADSTS50076: multifactor authentication is required
Likely causes
- A new or changed Conditional Access policy now requires MFA.
- The user signed in from a new location or network.
- The app uses legacy authentication that can't show an MFA prompt.
- The user closed or missed the MFA prompt.
How to fix it
- Have the user sign in again and complete the MFA prompt. In many apps this is a normal step, not a failure.
- If the prompt never appears, update the app or switch to one that supports modern authentication. Old mail clients using basic authentication can’t do MFA.
- If the user’s MFA method doesn’t work (new phone, lost phone), an admin can require re-registration of MFA from the user’s authentication methods.
- Admins: check the sign-in logs Conditional Access tab to see which policy required MFA.
- Don’t exclude the user from the MFA policy as a fix. Get the app or method working instead.
Checked against: learn.microsoft.com, learn.microsoft.com