**TL;DR:** Symptom: error: You must be logged in to the server (Unauthorized) on AKS Cause: The kubelogin token for the Entra-integrated cluster expired, or the kubeconfig context is stale after a cluster recreate. Authenticated-but-forbidden (cannot list resource) is a different error with Not for different error messages. TL;DR: Symptom: error: You must be logged in to the server (Unauthorized) on AKS Cause: The kubelogin token for the Entra-integrated cluster expired, or the kubeconfig context is stale after a cluster recreate. FIX FIX: refresh credentials with --overwrite-existing.

## The error

```text
error: You must be logged in to the server (Unauthorized) on AKS Cause: The kubelogin token for the Entra-integrated cluster expired, or the kubeconfig context is stale after a cluster recreate. Authenticated-but-forbidden (cannot list resource) is a different error with SYMPTOM error: You must be l
```

## The fix

**TL;DR:** Symptom: error: You must be logged in to the server (Unauthorized) on AKS Cause: The kubelogin token for the Entra-integrated cluster expired, or the kubeconfig context is stale after a cluster recreate. Authenticated-but-forbidden (cannot list resource) is a different error with SYMPTOM error: You must be logged in to the server (Unauthorized) on AKS CAUSE The kubelogin token for the Entra-integrated cluster expired, or the kubeconfig context is stale after a cluster recreate. FIX FIX: refresh credentials with --overwrite-existing.

## The fix

SYMPTOM
error: You must be logged in to the server (Unauthorized) on AKS

CAUSE
The kubelogin token for the Entra-integrated cluster expired, or the kubeconfig context is stale after a cluster recreate. Authenticated-but-forbidden (cannot list resource) is a different error with a different fix.

CONFIRM IT
CONFIRM: `kubectl config current-context` shows the intended cluster; `az aks get-credentials -g [rg] -n [cluster] --overwrite-existing` then retry - if it works, it was token/context staleness. `az aks install-cli` if kubelogin is missing from PATH.

FIX
FIX: refresh credentials with --overwrite-existing. For automation that hits this hourly, stop using user tokens: switch to a managed identity, workload identity, or a dedicated service account with Azure RBAC roles (Azure Kubernetes Service RBAC Cluster Admin/Reader).

VERIFY
VERIFY: `kubectl auth can-i get pods` returns a clean yes/no instead of an auth error.

## When to use this

- You are seeing this exact error message; match the block above, not just part of it.
- The failing call matches the scenario in the title: Diagnose.
- You want the fastest verified fix before digging through logs.

## When not to use this

- Your error text differs from the block above; close cousins often have different causes.
- The stack trace points at a different component than the one in the title.
- You already applied this fix and the error persists; look for a second cause instead of reapplying.

## Compatibility

- Not pinned to a specific version; follows current Diagnose behavior.