## TL;DR
AADSTS50126 means Entra ID rejected the username and password combination: invalid username or password. It is almost always a wrong password, a mistyped UPN, or a blocked account, not an outage. Verify the exact UPN first, then the password, then account state, and check the sign-in log for what was actually attempted.

## The query
```text
"AADSTS50126" invalid credentials: helpdesk troubleshooting steps
```

## Use this when
- sign-in fails with error code AADSTS50126
- user insists the password is right but Entra disagrees
- distinguishing a typo from a real account problem

## Not for
- MFA challenge failures (different error codes)
- conditional access blocks (different error codes)
- federated sign-in errors from ADFS (check the federation logs)

## Steps
1. Confirm the exact sign-in name: the full UPN such as user at domain, not a nickname or old domain. Expected output: the correct UPN is identified
2. Have the user type the password carefully, watching for caps lock and keyboard layout, or do a controlled reset. Expected output: a fresh known-good password
3. Check the account in Entra: not blocked, not deleted, password not expired. Expected output: account state is healthy
4. Open the sign-in log for the 50126 event and read the username that was actually attempted. Expected output: the log shows which username failed
5. If the attempted UPN differs from the real one, correct it and retry. Expected output: sign-in succeeds

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_mncgqMqcpZGMZ_3C28FIxQ
