## TL;DR
The app asked Entra ID to redirect to a URL that is not registered on its app registration. Copy the exact requested URL from the sign-in log, add it verbatim to the registered redirect URIs, and the error clears immediately.

## The query
```text
AADSTS50011 "the reply URL specified in the request does not match" entra sso fix
```

## Use this when
- sign-in fails with AADSTS50011
- the error appears after an app migration, domain change, or new environment
- one environment works and another fails with the same code

## Not for
- AADSTS50076 MFA-required or conditional access denials
- consent or admin-consent errors
- application code 500s after a successful sign-in

## Steps
1. Open the Entra ID sign-in log for the failed attempt and copy the redirect URI the app actually requested. Expected output: you have the exact requested URL string.
2. Open the app registration, then Authentication, and list the registered redirect URIs. Expected output: you can see which registered URI it should have matched.
3. Compare character by character: scheme, host, port, path, and trailing slash must all match exactly. Expected output: you find the one difference (usually http vs https or a trailing slash).
4. Add the exact requested URI to the registration and save. Expected output: the new URI appears in the registered list.
5. Have the user retry sign-in. Expected output: the redirect completes and the app session starts.

## Applies to
Microsoft Entra ID app registrations, OIDC and SAML apps, all current portal versions. Same fix works for B2C custom policies.

## Variant phrasings
### AADSTS50011 on SAML apps
Check the reply URL (Assertion Consumer Service URL) list on the SAML SSO settings instead of the OIDC redirect list.

### Reply URL mismatch after moving from staging to production
Each environment needs its own registered URI; registering only staging is the classic miss.

## Why it happens
Entra ID only redirects tokens to pre-registered URIs, as a phishing defense. Apps often build the redirect dynamically and a tiny difference (port, casing, trailing slash) breaks the match.

## Edge cases
- Wildcard redirect URIs are not allowed; register each one explicitly.
- Single-page apps using the auth code flow need the SPA platform type or the match fails differently.
- Changes can take a few minutes to propagate; if it still fails, clear the app session and retry.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_JuUrckUBv0zhnfAL1uhFzw
