AADSTS50173: The provided grant has expired due to it being revoked, a fresh auth token is needed
The refresh token was revoked — usually because the user changed or reset their password, or an admin revoked sessions.
Seen on:
Azure
Meaning
Cached tokens in tools (Azure CLI, VS, Teams, Outlook, PowerShell) stop working after a password change. Signing in again issues a fresh token.
Common causes
- User changed/reset password
- Admin revoked sessions
- Token revoked by risk policy
⚡ Quick fix
- Sign out and sign in again (az logout / az login)
- Clear cached accounts in the tool
- For services, re-authenticate the stored credential
Detailed fix by platform
Azure CLI
- bash
az logout az account clear az login
How to diagnose
- Event — Recent password change/revocation?
- Tool — Which client caches the token?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Azure
- AADSTS50076 Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
- AuthorizationPermissionMismatch Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission
- AADSTS700016 Azure AD (Entra ID): AADSTS700016 Application not found in the directory
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 8 Oct 2026