Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
A Conditional Access policy requires MFA, but the sign-in flow (often a script, legacy client or ROPC password grant) can’t complete it.
Seen on:
Azure
Meaning
Non-interactive flows that send a username/password directly can’t answer an MFA prompt. Automation should use a service principal or managed identity; humans should use interactive or device-code sign-in.
Common causes
- Script using username/password (ROPC) for a user with MFA
- Conditional Access policy newly applied
- Legacy protocol client (basic auth)
- Sign-in from an untrusted location triggering MFA
⚡ Quick fix
- Use
az logininteractively oraz login --use-device-code - Switch automation to a service principal / managed identity / workload identity federation
- Ask an admin which Conditional Access policy applies
Detailed fix by platform
Azure
- CI/CD: use OIDC workload identity federation (GitHub Actions
azure/loginwith federated credentials) instead of user accounts.
How to diagnose
- Flow — Interactive or password grant?
- Account — User or service principal?
- Policy — Entra sign-in logs → Conditional Access tab
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026