Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start with one failed sign-in event and locate where the flow stopped: an identity-provider error, an MFA interruption, or an application rejecting a SAML response or OIDC token point to different fixes.

Start with the failed sign-in event

Before changing federation settings, capture one affected attempt. Record the timestamp and time zone, user identifier, application, correlation ID or request ID, exact error code, failure reason, and any additional details. Those details help distinguish a failed authentication from a response the application could not process.

In Microsoft Entra, filter Sign-in logs by the user or application and failure status. Microsoft documents Reports Reader as the least-privileged role for accessing activity logs, though role requirements may vary by tenant configuration and can change. If the event details do not explain the failure, use Microsoft Entra Sign-in diagnostics with the user and application plus the correlation or request ID and time. The diagnostics can investigate issues such as incomplete MFA setup, per-user MFA, and incorrect credentials.

Locate the stage where sign-in fails

What the user sees Likely failure point Evidence to inspect
An error on the identity-provider sign-in page The request may be malformed, unrecognized, or incompatible with the provider’s configuration. The protocol request, its destination and issuer, the callback or reply endpoint, and the identity-provider event.
The user authenticates, then the application displays an error The identity provider may have issued a response or token that the application rejected. The SAML response or token-validation error, identity/claim values, signature or signing-key expectations, and application logs.
An MFA prompt loops, is abandoned, or never completes The second-factor prompt, initial setup, or an applicable policy may have interrupted the flow. The event’s failure reason and additional details, plus sign-in diagnostics for the MFA requirement or setup state.
An OIDC callback reports a redirect mismatch or protocol error The requested redirect URI may not match the application registration, or a later token-validation step may be failing. The redirect URI in the authorization request, the registered URI, and—if a token was issued—the application’s validation error and provider metadata.

Do not treat these patterns as interchangeable: an identity-provider failure happens before successful issuance, while an application-side rejection happens after the identity provider has returned something for the app to process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Troubleshoot SAML request and response failures

When the identity provider rejects the request

Capture the SAML request using the identity platform’s test or diagnostic feature, or another approved inspection method. Compare the request’s Destination with the identity provider’s SAML single sign-on service URL, its Issuer with the configured application identifier, and its AssertionConsumerServiceURL with the application’s expected endpoint. Microsoft recommends its SAML test experience and request/response capture to collect actionable evidence.

For Microsoft Entra integrations, AADSTS75005 means the SAML request is not a supported or valid SAML protocol message. Microsoft’s troubleshooting guidance identifies missing required fields and request encoding as possible causes. Capture the request and check compatibility with the service-provider vendor rather than changing fields speculatively.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

When the application rejects the SAML response

Inspect the returned response against the service provider’s requirements. Check the NameID value and format, the issued claims or attributes, and the signature and signing certificate. The application may be unable to identify the user if an expected identity value or attribute is absent; a signature-method mismatch can also lead to rejection. Confirm the required values and algorithms with the service-provider vendor before changing claim mappings or signing settings.

Check the federation configuration

For a Microsoft Entra SAML application, compare the app Identifier, Reply URL, metadata XML or certificate, and claims mapping with the service provider’s current configuration. Microsoft documents downloading metadata XML from the SAML signing certificate section of the application settings. These are Entra-specific settings; labels and navigation can change, and other identity providers use their own consoles and terminology.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Troubleshoot OIDC redirect and token failures

Check the authorization request and redirect URI

Compare the client or application ID, expected tenant or authority, requested openid scope, and redirect URI in the actual authorization request with the application registration. The redirect URI must exactly match one registered for the app; account for URL encoding when comparing the request value. In Microsoft Entra, AADSTS50011 identifies a redirect URI mismatch. Microsoft’s corresponding error text is “The redirect URI specified in the request does not match.”

If the application receives a token but rejects it

Use the application’s token-validation error to identify what failed, then validate the token signature and claims against the application’s requirements. Check the provider’s OpenID configuration document and signing-key metadata rather than relying on a manually pinned key that may become obsolete after key rotation. Validation requirements depend on the client type and architecture, so follow the identity platform and application guidance rather than applying one universal checklist.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Separate consent errors from callback errors

If the response points to consent, check whether the application requested a resource or permission that still needs user or administrator consent. A consent-related OIDC/OAuth2 response is a different problem from a redirect mismatch; a similar-looking SAML error can have a different configuration cause.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check MFA as its own interruption

Use the sign-in event’s failure reason and additional details to determine whether the user did not complete the prompt, had not finished initial setup, or was stopped by a policy requirement. In Microsoft Entra, error 500121 is documented for an incomplete MFA prompt; incomplete MFA setup is also a common situation described in Microsoft’s troubleshooting guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

Microsoft Entra Sign-in diagnostics can identify an interrupted first-time MFA setup, sometimes described as “proofup,” and show whether the requirement came from Conditional Access or per-user MFA settings. Follow the diagnostic’s indicated source and remediation details; policy design is organization-specific. Do not assume every MFA loop means the authenticator or second factor itself is faulty.

Escalate with useful, safe evidence

If the event and protocol evidence do not identify the cause, give the identity-provider or application support team the timestamp and time zone, correlation or request ID, exact error and failure details, and relevant configuration values. Include a sanitized request or response excerpt, or token details only when appropriate for that vendor’s secure support process. Never put passwords, client secrets, or bearer tokens in a ticket. Microsoft specifically identifies correlation ID and timestamp as useful when opening a support case; other providers may request different evidence.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.