product · inferred from evidence
AADSTS7000215
An error code indicating an invalid client secret in Azure Active Directory authentication.
- Diagnose: AADSTS7000215: invalid client secret
Symptom: AADSTS7000215: invalid client secret Cause: The service principal's secret expired (max 24 months) or the code uses the wrong secret/tenant. It worked for months then broke overnight = expiry.
- Azure Key Vault: expired or disabled secret versions fail silently or 403
An expired secret does not always error loudly: get_secret returns the newest ENABLED version, so expiry can mean silently getting an old value. Check expiry and enabled flags, not just existence.
- Azure AADSTS7000215: the service principal secret is expired or wrong
Invalid client secret errors mean the app registration's secret expired (max 2 years) or you are using the wrong one. The fix is a new secret, but the real fix is federated credentials so this never recurs.