AADSTS70021 🔷 Azure

AADSTS70021: No matching federated identity record found for presented assertion (GitHub Actions / workload identity)

The OIDC token from GitHub Actions/Kubernetes/another IdP doesn’t match any federated credential on the app — issuer, subject or audience differ.

Seen on: Azure

Meaning

Federated credentials match exactly on issuer and subject (e.g. repo:org/repo:ref:refs/heads/main or repo:org/repo:environment:prod). Running from another branch, a pull request, or an environment changes the subject.

Common causes

  • Subject doesn’t match (branch vs environment vs pull_request)
  • Wrong issuer URL
  • Audience not api://AzureADTokenExchange
  • Federated credential added to a different app

⚡ Quick fix

  1. Read the assertion’s subject from the error and add a matching federated credential
  2. Use environment-based subjects for deployment jobs
  3. Check the client ID used by azure/login

Detailed fix by platform

Azure CLI

  1. az ad app federated-credential create --id <app-id> --parameters '{"name":"main","issuer":"https://token.actions.githubusercontent.com","subject":"repo:myorg/myrepo:ref:refs/heads/main","audiences":["api://AzureADTokenExchange"]}'

How to diagnose

  1. Subject — Value in the error message
  2. Credentials — az ad app federated-credential list
  3. Client ID — Same app?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.