Diagnose: error: You must be logged in to the server (Unauthorized) on AKS
Symptom: error: You must be logged in to the server (Unauthorized) on AKS Cause: The kubelogin token for the Entra-integrated cluster expired, or the kubeconfig context is stale after a cluster recreate. Authenticated-but-forbidden (cannot list resource) is a different error with Not for different error messages.
TL;DR: Symptom: error: You must be logged in to the server (Unauthorized) on AKS Cause: The kubelogin token for the Entra-integrated cluster expired, or the kubeconfig context is stale after a cluster recreate. Authenticated-but-forbidden (cannot list resource) is a different error with Not for different error messages. TL;DR: Symptom: error: You must be logged in to the server (Unauthorized) on AKS Cause: The kubelogin token for the Entra-integrated cluster expired, or the kubeconfig context is stale after a cluster recreate. FIX FIX: refresh credentials with --overwrite-existing.
The error
error: You must be logged in to the server (Unauthorized) on AKS Cause: The kubelogin token for the Entra-integrated cluster expired, or the kubeconfig context is stale after a cluster recreate. Authenticated-but-forbidden (cannot list resource) is a different error with SYMPTOM error: You must be lThe fix
TL;DR: Symptom: error: You must be logged in to the server (Unauthorized) on AKS Cause: The kubelogin token for the Entra-integrated cluster expired, or the kubeconfig context is stale after a cluster recreate. Authenticated-but-forbidden (cannot list resource) is a different error with SYMPTOM error: You must be logged in to the server (Unauthorized) on AKS CAUSE The kubelogin token for the Entra-integrated cluster expired, or the kubeconfig context is stale after a cluster recreate. FIX FIX: refresh credentials with --overwrite-existing.
The fix
SYMPTOM error: You must be logged in to the server (Unauthorized) on AKS
CAUSE The kubelogin token for the Entra-integrated cluster expired, or the kubeconfig context is stale after a cluster recreate. Authenticated-but-forbidden (cannot list resource) is a different error with a different fix.
CONFIRM IT CONFIRM: kubectl config current-context shows the intended cluster; az aks get-credentials -g [rg] -n [cluster] --overwrite-existing then retry - if it works, it was token/context staleness. az aks install-cli if kubelogin is missing from PATH.
FIX FIX: refresh credentials with --overwrite-existing. For automation that hits this hourly, stop using user tokens: switch to a managed identity, workload identity, or a dedicated service account with Azure RBAC roles (Azure Kubernetes Service RBAC Cluster Admin/Reader).
VERIFY VERIFY: kubectl auth can-i get pods returns a clean yes/no instead of an auth error.
When to use this
- You are seeing this exact error message; match the block above, not just part of it.
- The failing call matches the scenario in the title: Diagnose.
- You want the fastest verified fix before digging through logs.
When not to use this
- Your error text differs from the block above; close cousins often have different causes.
- The stack trace points at a different component than the one in the title.
- You already applied this fix and the error persists; look for a second cause instead of reapplying.
Compatibility
- Not pinned to a specific version; follows current Diagnose behavior.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.