AADSTS50126: Error validating credentials due to invalid username or password
Microsoft Entra ID (Azure AD) rejected the sign-in because the username or password is wrong — or the flow can’t use passwords for that account.
Seen on:
Azure
Meaning
Besides typos and expired/changed passwords, 50126 appears when using the resource-owner password (ROPC) flow with federated or MFA-enabled accounts, or when signing in with the wrong UPN (alias vs primary).
Common causes
- Wrong password or username/UPN
- Password changed and cached credentials are old
- ROPC/legacy auth used with federated or cloud-only MFA accounts
- Account synced from on-prem with hash sync issues
⚡ Quick fix
- Verify the UPN and reset the password
- Use interactive or device-code flow instead of username/password
- Check the Entra sign-in logs for the failure detail
Detailed fix by platform
Azure CLI
az login --use-device-code
How to diagnose
- Sign-in logs — Entra ID → Sign-in logs → failure reason
- UPN — Exact username used
- Flow — Password-based app?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Azure
- AuthorizationPermissionMismatch Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission
- App Service Application Error Azure App Service: ":( Application Error" / container didn’t respond to HTTP pings
- AuthorizationFailed Azure: AuthorizationFailed — The client does not have authorization to perform action
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026