AADSTS50126 🔷 Azure

AADSTS50126: Error validating credentials due to invalid username or password

Microsoft Entra ID (Azure AD) rejected the sign-in because the username or password is wrong — or the flow can’t use passwords for that account.

Seen on: Azure

Meaning

Besides typos and expired/changed passwords, 50126 appears when using the resource-owner password (ROPC) flow with federated or MFA-enabled accounts, or when signing in with the wrong UPN (alias vs primary).

Common causes

  • Wrong password or username/UPN
  • Password changed and cached credentials are old
  • ROPC/legacy auth used with federated or cloud-only MFA accounts
  • Account synced from on-prem with hash sync issues

⚡ Quick fix

  1. Verify the UPN and reset the password
  2. Use interactive or device-code flow instead of username/password
  3. Check the Entra sign-in logs for the failure detail

Detailed fix by platform

Azure CLI

  1. az login --use-device-code

How to diagnose

  1. Sign-in logs — Entra ID → Sign-in logs → failure reason
  2. UPN — Exact username used
  3. Flow — Password-based app?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.