| AADSTS50102 | Unable to load CustomClaimsTransformer '{type}' was specified for principal '{principalId}'. |
| AADSTS50103 | There was an error transforming the claims for the token: {errorMessage} |
| AADSTS50105 | EntitlementGrantsNotFound - The signed in user isn't assigned to a role for the signed in app. Assign the user to the app. To learn more, see the troubleshooting article for error [AADSTS50105](/troubleshoot/azure/active-directory/error-code-aadsts50105-user-not-assigned-role). |
| AADSTS50107 |The requested federation realm object '{name}' does not exist. Application error - the login request was malformed and could not be matched with an existing authentication endpoint or instance. |
| AADSTS50108 | Claims transformation configuration could not be retrieved. |
| AADSTS50109 | Claim transformation is unknown from configuration. |
| AADSTS50111 | Unknown claim transformation was asked to be applied. |
| AADSTS50138 | Invalid encryption key environment. |
| AADSTS50139 | SessionMissingMsaOAuth2RefreshToken - The session is invalid due to a missing external refresh token. |
| AADSTS50140 | KmsiInterrupt - This error occurred due to "Keep me signed in" interrupt when the user was signing-in. This is an expected part of the sign in flow, where a user is asked if they want to remain signed into their current browser to make further logins easier. For more information, see [The new Microsoft Entra sign-in and βKeep me signed inβ experiences rolling out now!](https://techcommunity.microsoft.com/t5/azure-active-directory-identity/the-new-azure-ad-sign-in-and-keep-me-signed-in-experiences/m-p/128267). You can [open a support ticket](~/fundamentals/how-to-get-support.md) with Correlation ID, Request ID, and Error code to get more details.|
| AADSTS50141 | Protected key is not intended for the authenticated user. |
| AADSTS50142 | Password change is required due to a conditional access policy. |
| AADSTS50143 | Session mismatch - Session is invalid because user tenant doesn't match the domain hint due to different resource.Β [Open a support ticket](~/fundamentals/how-to-get-support.md) with Correlation ID, Request ID, and Error code to get more details. |
| AADSTS50144 | InvalidPasswordExpiredOnPremPassword - User's Active Directory password has expired. Generate a new password for the user or have the user use the self-service reset tool to reset their password. |
| AADSTS50147 | Invalid size of the code challenge parameter. Contact the application owner to correct their use of the PKCE parameters. |
| AADSTS50148 | The code_verifier does not match the code_challenge supplied in the authorization request for PKCE. Contact the application owner to correct their use of the PKCE parameters. |
| AADSTS50146 | MissingCustomSigningKey - This app is required to be configured with an app-specific signing key. It's either not configured with one, or the key has expired or isn't yet valid. Please contact the owner of the application. |
| AADSTS501461 | AcceptMappedClaims is only supported for a token audience matching the application GUID or an audience within the tenant's verified domains. Either change the resource identifier, or use an application-specific signing key. |
| AADSTS50147 | MissingCodeChallenge - The size of the code challenge parameter isn't valid. |
| AADSTS50155 | DeviceAuthenticationFailed - Device authentication failed for this user. |
| AADSTS50102 | Unable to load CustomClaimsTransformer '{type}' was specified for principal '{principalId}'. |
| AADSTS50103 | There was an error transforming the claims for the token: {errorMessage} |
| AADSTS50105 | EntitlementGrantsNotFound - The signed in user isn't assigned to a role for the signed in app. Assign the user to the app. To learn more, see the troubleshooting article for error [AADSTS50105](/troubleshoot/azure/active-directory/error-code-aadsts50105-user-not-assigned-role). |
| AADSTS50107 |The requested federation realm object '{name}' doesn't exist. Application error - the login request was malformed and couldn't be matched with an existing authentication endpoint or instance. |
| AADSTS50108 | Claims transformation configuration could not be retrieved. |
| AADSTS50109 | Claim transformation is unknown from configuration. |
| AADSTS50111 | Unknown claim transformation was asked to be applied. |
| AADSTS50138 | Invalid encryption key environment. |
| AADSTS50139 | SessionMissingMsaOAuth2RefreshToken - The session is invalid due to a missing external refresh token. |
| AADSTS50140 | KmsiInterrupt - This error occurred due to "Keep me signed in" interrupt when the user was signing-in. This is an expected part of the sign in flow, where a user is asked if they want to remain signed into their current browser to make further logins easier. For more information, see [The new Microsoft Entra sign-in and βKeep me signed inβ experiences rolling out now!](https://techcommunity.microsoft.com/t5/azure-active-directory-identity/the-new-azure-ad-sign-in-and-keep-me-signed-in-experiences/m-p/128267). You can [open a support ticket](~/fundamentals/how-to-get-support.md) with Correlation ID, Request ID, and Error code to get more details.|
| AADSTS50141 | Protected key isn't intended for the authenticated user. |
| AADSTS50142 | Password change is required due to a conditional access policy. |
| AADSTS50143 | Session mismatch - Session is invalid because user tenant doesn't match the domain hint due to different resource.Β [Open a support ticket](~/fundamentals/how-to-get-support.md) with Correlation ID, Request ID, and Error code to get more details. |
| AADSTS50144 | InvalidPasswordExpiredOnPremPassword - User's Active Directory password has expired. Generate a new password for the user or have the user use the self-service reset tool to reset their password. |
| AADSTS50147 | Invalid size of the code challenge parameter. Contact the application owner to correct their use of the PKCE parameters. |
| AADSTS50148 | The code_verifier doesn't match the code_challenge supplied in the authorization request for PKCE. Contact the application owner to correct their use of the PKCE parameters. |
| AADSTS50146 | MissingCustomSigningKey - This app is required to be configured with an app-specific signing key. It's either not configured with one, or the key has expired or isn't yet valid. Please contact the owner of the application. |
| AADSTS501461 | AcceptMappedClaims is only supported for a token audience matching the application GUID or an audience within the tenant's verified domains. Either change the resource identifier, or use an application-specific signing key. |
| AADSTS50147 | MissingCodeChallenge - The size of the code challenge parameter isn't valid. |
| AADSTS50155 | DeviceAuthenticationFailed - Device authentication failed for this user. |