AADSTS50011 "the reply URL specified in the request does not match" entra sso fix
Resolves the Entra ID AADSTS50011 reply URL mismatch: capturing the exact requested redirect and registering it on the app registration. Use when SSO fails with the reply URL error. Not for consent prompts, conditional access blocks, or expired client secrets.
TL;DR
The app asked Entra ID to redirect to a URL that is not registered on its app registration. Copy the exact requested URL from the sign-in log, add it verbatim to the registered redirect URIs, and the error clears immediately.
The query
AADSTS50011 "the reply URL specified in the request does not match" entra sso fixUse this when
- sign-in fails with AADSTS50011
- the error appears after an app migration, domain change, or new environment
- one environment works and another fails with the same code
Not for
- AADSTS50076 MFA-required or conditional access denials
- consent or admin-consent errors
- application code 500s after a successful sign-in
Steps
- Open the Entra ID sign-in log for the failed attempt and copy the redirect URI the app actually requested. Expected output: you have the exact requested URL string.
- Open the app registration, then Authentication, and list the registered redirect URIs. Expected output: you can see which registered URI it should have matched.
- Compare character by character: scheme, host, port, path, and trailing slash must all match exactly. Expected output: you find the one difference (usually http vs https or a trailing slash).
- Add the exact requested URI to the registration and save. Expected output: the new URI appears in the registered list.
- Have the user retry sign-in. Expected output: the redirect completes and the app session starts.
Applies to
Microsoft Entra ID app registrations, OIDC and SAML apps, all current portal versions. Same fix works for B2C custom policies.
Variant phrasings
AADSTS50011 on SAML apps
Check the reply URL (Assertion Consumer Service URL) list on the SAML SSO settings instead of the OIDC redirect list.
Reply URL mismatch after moving from staging to production
Each environment needs its own registered URI; registering only staging is the classic miss.
Why it happens
Entra ID only redirects tokens to pre-registered URIs, as a phishing defense. Apps often build the redirect dynamically and a tiny difference (port, casing, trailing slash) breaks the match.
Edge cases
- Wildcard redirect URIs are not allowed; register each one explicitly.
- Single-page apps using the auth code flow need the SPA platform type or the match fails differently.
- Changes can take a few minutes to propagate; if it still fails, clear the app session and retry.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_JuUrckUBv0zhnfAL1uhFzw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.