Short answer
AADSTS50076 means this sign-in needs an MFA claim that the current session did not satisfy. Have the user complete the expected interactive MFA challenge and retry. If this is unexpected or repeats, inspect the matching Microsoft Entra sign-in event and its Conditional Access and Authentication Details tabs to see which policy or context triggered MFA. Do not disable MFA as a first response.
This guide summarizes Microsoft documentation; this site has not tested it in a tenant.
Problem / symptoms
A token request or application sign-in is interrupted with an MFA requirement. The event may follow an administrator policy change, a changed sign-in location, or a tenant’s per-user or Conditional Access configuration.
Exact error
AADSTS50076: Due to a configuration change made by your administrator, or because you moved to a new location, you must use multifactor authentication to access the resource.
Environment and scope
Microsoft Entra interactive and non-interactive sign-ins. The MFA requirement may come from Conditional Access, per-user MFA, Security Defaults, or another authentication policy. A Teams Rooms resource account has additional product-specific constraints; follow the Teams Rooms documentation for that device scenario.
What the evidence establishes
Microsoft defines this code as a request to use MFA, often after a configuration or location change. The code does not mean that MFA itself is broken, and it does not identify a particular policy without the sign-in record.
Investigation
- Capture the sign-in time, user, application/resource, correlation ID, error code, and failure reason.
- In Entra ID → Monitoring & health → Sign-in logs, filter to the user, app, time, and failed status. Open the matching event.
- Review Conditional Access to identify policies that applied, and Authentication Details to see the authentication sequence and result.
- Use Troubleshoot Event or sign-in diagnostics if the policy result is unclear. Confirm whether the user completed the challenge and whether the current session was interactive.
- If the account is a service or room resource account, verify that the resource-account design is supported before changing its MFA or Conditional Access requirements.
Root cause
The request arrives without the required MFA claim for the current access policy and context. The cause can be a legitimate step-up challenge or a policy/resource-account mismatch. Only the sign-in record and tenant policy show which applies.
Resolution
For a normal user sign-in, complete MFA and retry with a fresh sign-in request. For a repeated or unexpected interruption, correct the specific assignment, authentication method, device condition, or resource-account design identified in the logs. Keep the intended security requirement in place; adjust policy only after an administrator confirms the desired access rule.
Verification
- Confirm the next sign-in succeeds after the required MFA step.
- Confirm the log records the expected authentication method and policy outcome.
- If a policy change was required, test both an in-scope and out-of-scope account/device to ensure the rule still protects the intended population.