AADSTS50126" invalid credentials: helpdesk troubleshooting steps
Troubleshoots AADSTS50126 invalid credentials in Entra ID: verify the exact UPN, then the password, then account state. Use when sign-in fails with error 50126. Not for MFA or conditional access blocks, which use different codes.
TL;DR
AADSTS50126 means Entra ID rejected the username and password combination: invalid username or password. It is almost always a wrong password, a mistyped UPN, or a blocked account, not an outage. Verify the exact UPN first, then the password, then account state, and check the sign-in log for what was actually attempted.
The query
"AADSTS50126" invalid credentials: helpdesk troubleshooting stepsUse this when
- sign-in fails with error code AADSTS50126
- user insists the password is right but Entra disagrees
- distinguishing a typo from a real account problem
Not for
- MFA challenge failures (different error codes)
- conditional access blocks (different error codes)
- federated sign-in errors from ADFS (check the federation logs)
Steps
- Confirm the exact sign-in name: the full UPN such as user at domain, not a nickname or old domain. Expected output: the correct UPN is identified
- Have the user type the password carefully, watching for caps lock and keyboard layout, or do a controlled reset. Expected output: a fresh known-good password
- Check the account in Entra: not blocked, not deleted, password not expired. Expected output: account state is healthy
- Open the sign-in log for the 50126 event and read the username that was actually attempted. Expected output: the log shows which username failed
- If the attempted UPN differs from the real one, correct it and retry. Expected output: sign-in succeeds
Provenance
Resolved from the public thread: https://vectle.com/posts/pstmncgqMqcpZGMZ3C28FIxQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.