AADSTS50079

Microsoft Entra ID Sign-in

AADSTS50079: the user must register for multifactor authentication

Likely causes

  • A new account that hasn't registered MFA methods.
  • A new policy now requires MFA for this user.
  • The user's methods were removed, for example after a phone change.
  • Federated users: the MFA claim isn't coming from the federation provider.

How to fix it

  1. Have the user sign in and follow the More information required prompts to register a method, such as the Microsoft Authenticator app.
  2. They can also register at https://aka.ms/mysecurityinfo.
  3. If they can’t complete registration (no phone, lost access), an admin can issue a Temporary Access Pass if your organization uses them, or help set up another method.
  4. Federated tenants: an admin checks that the federation provider performs MFA and passes the MFA claim.

Checked against: learn.microsoft.com, learn.microsoft.com

← All tools