AADSTS7000215
Invalid client secret
Answer: The credential supplied by the confidential client does not match a valid client secret for the application.
Resolution playbook
Fix it, then prove it
Use the error record as the starting point; use tenant evidence to confirm the actual cause.
Likely causes
- Never paste production secrets into diagnostic tickets or logs.
- The request is using a tenant, identity, application, resource, or policy context that does not match the intended operation.
- The error response is the symptom; the correlation/request ID and matching service log identify the controlling decision.
Recommended fix
- Send the secret value, not the secret identifier.
- Confirm the credential belongs to the client ID and tenant in the request.
- Rotate the secret securely if its value is unavailable.
Verify
- Repeat the smallest operation that produced the failure.
- Confirm a fresh success in the authoritative service log or admin center, not only in the client UI.
- Record the new UTC timestamp and correlation/request ID so the retry can be distinguished from cached or older failures.
Escalate when
- The failure persists after the documented prerequisites and a new authentication/session attempt.
- Multiple users, apps, devices, or networks show the same error, suggesting tenant policy or service scope.
- You can provide the exact UTC time, tenant, application/resource, correlation or request ID, and sanitized logs.
Admin context
Never paste production secrets into diagnostic tickets or logs.
Evidence to preserve
- UTC timestamp and correlation/request ID
- Tenant, application, resource, and authentication flow
- Sanitized service log details and exact operation
Advertisement
