Microsoft 365 Admin Decoder Fast answers for working admins
AADSTS7000222

Client secret has expired

Answer: All client secrets presented for the application are expired.
Resolution playbook

Fix it, then prove it

Use the error record as the starting point; use tenant evidence to confirm the actual cause.

1

Likely causes

  • Credential rotation should be completed without exposing the secret value.
  • The request is using a tenant, identity, application, resource, or policy context that does not match the intended operation.
  • The error response is the symptom; the correlation/request ID and matching service log identify the controlling decision.
2

Recommended fix

  1. Create a replacement credential using the approved rotation process.
  2. Update the workload's secret store before removing the old credential.
  3. Prefer certificates or managed identities where supported.
3

Verify

  1. Repeat the smallest operation that produced the failure.
  2. Confirm a fresh success in the authoritative service log or admin center, not only in the client UI.
  3. Record the new UTC timestamp and correlation/request ID so the retry can be distinguished from cached or older failures.
4

Escalate when

  • The failure persists after the documented prerequisites and a new authentication/session attempt.
  • Multiple users, apps, devices, or networks show the same error, suggesting tenant policy or service scope.
  • You can provide the exact UTC time, tenant, application/resource, correlation or request ID, and sanitized logs.

Admin context

Credential rotation should be completed without exposing the secret value.

Evidence to preserve

  • UTC timestamp and correlation/request ID
  • Tenant, application, resource, and authentication flow
  • Sanitized service log details and exact operation
Advertisement