VectleSkillsAzure AADSTS7000215: the service principal secret is expired or wrong

Azure AADSTS7000215: the service principal secret is expired or wrong

Export

Microsoft Entra ID sign-in fails with AADSTS7000215 invalid client secret. Covers triaging expiry vs wrong secret vs wrong tenant, rotating safely, and replacing secrets with federated credentials. Not for certificate auth issues or consent errors.

TL;DR: AADSTS7000215 means the app registration's secret expired (max 24 months) or you are using the wrong one. Check expiry in the portal under Certificates and secrets. Create a new secret, update the consumer, then DELETE the old one. Never delete first. The real fix is a federated credential (workload identity federation) so there is no secret to expire.

The error, verbatim:

AADSTS7000215: Invalid client secret provided.

Steps:

  1. Check expiry in the portal: Entra, App registrations, Certificates and secrets. Success: you can see the secret's expiry date. If it worked for months then broke overnight, this is it.
  2. Rule out the wrong secret. App registrations can hold several; compare the secret's key id or hint in your config against the portal, never the value. Success: the hint matches exactly one current secret.
  3. Rule out the wrong tenant. A secret from tenant A used against tenant B gives the same error shape. Success: the authority URL matches the app's tenant.
  4. Create a new secret, update the consumer, then delete the old one. Do not delete first. Success: auth works and only the new secret exists.
  5. Kill the pattern: add a federated credential for the CI workload so there is no secret at all (Entra, App registrations, Certificates and secrets, Federated credentials). Success: the workload authenticates with OIDC and no secret rotation is ever needed again.

When to use: AADSTS7000215 on any OAuth2 client-credentials flow against Microsoft Entra ID.

When not to use: certificate-based auth failures, consent/permission errors (those are different AADSTS codes), or user sign-in problems.

Compatibility: Microsoft Entra ID app registrations; GitHub Actions, Azure DevOps, and Terraform Cloud all support OIDC federation to Entra.

Variants:

  • aadsts7000215 invalid client secret
  • azure ad secret expired
  • entra invalid client secret provided

Root cause: secrets max out at 24 months and something always forgets the rotation. The error also fires for wrong-secret and wrong-tenant, which is why step 1 is check, not rotate blindly.

Edge cases:

  • Calendar rule: if you must keep secrets, set the expiry reminder for 30 days before, not the day of. The 2am page is the tax on skipping step 5.
  • Multiple secrets on one registration are the classic wrong-secret trap. The key id or hint disambiguates; the value never should.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=Azure+AADSTS7000215%3A+the+service+principal+secret+is+expired+or+wrong&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.