logo
search
Exchange Connection Problems

How to Fix Connect-ExchangeOnline Error 0xffffffff80070520

Maira MehtabMaira Mehtab Sep 22, 2026 869 views

Question details

The user needs to resolve an unknown status error (0xffffffff80070520) that blocks PowerShell from connecting to Exchange Online when Multi-Factor Authentication (MFA) is enabled.

Product
Exchange Online PowerShell
Device & OS
Entra-joined Windows laptop
Scenario
Attempting to run the Connect-ExchangeOnline cmdlet with MFA enabled on an Entra-joined device under a standard user account.
Observed behavior
The connection command fails with error code 0xffffffff80070520, although the same command works successfully on non-Entra devices or when logged in as a local administrator.
Before you start

Ensure you have the necessary administrative privileges to install updated versions of PowerShell on your device and access to your MFA verification method.

Solution 1Recommended

Upgrade to PowerShell 7.5.0 and Use Device Authentication

Bypass the local token broker failure on Entra-joined devices by upgrading your PowerShell environment and utilizing the device-based login flow.

The error 0xffffffff80070520 typically occurs on Entra-joined devices due to a conflict in how the built-in Windows Web Account Manager (WAM) handles MFA token prompts for standard accounts. Forcing a device code authentication flow resolves the issue by circumventing the local token broker entirely.

1
Install PowerShell 7.5.0

Download and install PowerShell version 7.5.0 (or newer) from the official Microsoft PowerShell GitHub repository or the Microsoft Store.

2
Launch the New PowerShell

Open the newly installed PowerShell 7 terminal. Do not use the legacy Windows PowerShell (version 5.1).

3
Execute the Connection Command

Type the command `Connect-ExchangeOnline -UserPrincipalName <your_email> -device` (replacing <your_email> with your actual admin address) and press Enter.

4
Authenticate via Device Code

The terminal will provide a code and a URL. Open a web browser, navigate to the Microsoft device login page, enter the code, and complete your Multi-Factor Authentication.

Connection Successful: Once the device code is verified in your browser, the PowerShell session will successfully authenticate and connect to Exchange Online without returning the previous error.
Free Microsoft Office alternative

Streamline Your IT Documentation with WPS Office

While resolving Exchange Online PowerShell errors requires technical troubleshooting, managing your IT policies, PowerShell scripts, and administrative reports should be simple. WPS Office is a highly compatible, free alternative to Microsoft Office that provides robust document creation tools without the heavy subscription fees.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
  2. 2. Install WPS Office: Run the setup file and follow the quick installation prompts to set up the software on your device.
  3. 3. Manage IT Documents: Launch WPS Office to instantly open, edit, and save your existing Microsoft Office files with perfect formatting.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx) for seamless document sharing.Lightweight architecture ensures smooth performance even on heavily managed IT laptops.Built-in PDF toolkit perfect for updating technical guides, network diagrams, and IT manuals.Familiar tabbed interface requires zero learning curve, allowing for rapid deployment across your team.
QA img-9

Frequently Asked Questions

What causes the 0xffffffff80070520 error in Exchange Online PowerShell?

This error is typically triggered on Entra-joined (formerly Azure AD-joined) laptops when the local Web Account Manager (WAM) fails to properly pass the MFA token prompt to the PowerShell session.

Why does the Connect-ExchangeOnline command work on a local administrator account?

Local accounts bypass the Entra ID integrated Single Sign-On (SSO) token broker, avoiding the specific credential conflict that triggers this authentication error.

Do I have to use the -device parameter to fix this issue?

Yes, using the `-device` parameter is highly recommended as it forces the authentication process to use the device code flow, which securely bypasses the local token broker failure causing the error.