AADSTS50076 🔷 Azure

Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required

A Conditional Access policy requires MFA, but the sign-in flow (often a script, legacy client or ROPC password grant) can’t complete it.

Seen on: Azure

Meaning

Non-interactive flows that send a username/password directly can’t answer an MFA prompt. Automation should use a service principal or managed identity; humans should use interactive or device-code sign-in.

Common causes

  • Script using username/password (ROPC) for a user with MFA
  • Conditional Access policy newly applied
  • Legacy protocol client (basic auth)
  • Sign-in from an untrusted location triggering MFA

⚡ Quick fix

  1. Use az login interactively or az login --use-device-code
  2. Switch automation to a service principal / managed identity / workload identity federation
  3. Ask an admin which Conditional Access policy applies

Detailed fix by platform

Azure

  1. CI/CD: use OIDC workload identity federation (GitHub Actions azure/login with federated credentials) instead of user accounts.

How to diagnose

  1. Flow — Interactive or password grant?
  2. Account — User or service principal?
  3. Policy — Entra sign-in logs → Conditional Access tab

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.