logo
search
list

Table of Content

What AADSTS900561 Means During Microsoft Sign-In
Restart the Authentication Flow from the Correct Entry Point
Check the App Registration When the Error Persists
Use WPS Office Without Bypassing Microsoft Sign-In
AADSTS900561 Sign-In FAQs

How to Fix AADSTS900561 Endpoint Only Accepts POST

Posted by Huda Qurayshi

calendar

2026-09-17

views

870

likes

4

AADSTS900561 means a Microsoft identity endpoint received the wrong type of web request. It often appears when a browser opens an authentication or token endpoint directly, a saved link is stale, or an application builds an incorrect sign-in redirect. The request and correlation IDs are diagnostic values, not passwords or activation codes.

What AADSTS900561 Means During Microsoft Sign-In

Do not repeatedly refresh the error URL or edit its parameters. Record the Request ID, Correlation ID, timestamp, application name, and the page where sign-in started; remove tenant names or other sensitive details before sharing them publicly.

Restart the Authentication Flow from the Correct Entry Point

How to Fix AADSTS900561 Endpoint Only Accepts POST four-step workflow
Resolve AADSTS900561 by starting sign-in from the application, clearing a stale session, and having an administrator verify redirect URIs and logs.
  1. Close the error tab and start again from the application’s normal sign-in button or an official Microsoft 365 portal. Never bookmark the long authentication endpoint.
  2. Open a private browser window and retry. If it works, clear cookies for the application and Microsoft sign-in domains in the regular browser, then sign in again.
  3. Try the same account at m365.cloud.microsoft. If Microsoft 365 works but the third-party or internal app fails, the application flow is the likely cause.
  4. Give the administrator the Request ID, Correlation ID, timestamp, and app name. In Microsoft Entra admin center, review the matching sign-in log and verify that the app registration uses an exact, approved redirect URI and a supported authorization flow.

Follow the relevant official guidance in Microsoft’s documentation, and verify the result before changing a wider deployment or replacing the original file.

Check the App Registration When the Error Persists

Users cannot repair an application registration from the error page. For a company-built app, the developer should verify that authorization requests and token exchanges use the documented methods rather than sending a browser GET request to a POST-only endpoint.

Use WPS Office Without Bypassing Microsoft Sign-In

Use Word, Excel, and PPT for FREE

WPS Office cannot repair a Microsoft Entra application registration or bypass its authentication flow. It remains a free, lightweight Microsoft Office-compatible alternative for local DOCX, XLSX, PPTX, and PDF work.

WPS Office free alternative for AADSTS900561 endpoint only accepts POST with Writer Spreadsheets Presentation PDF and AI tools
Continue approved local office work in WPS Office while the Microsoft-side task is resolved.

Writer, Spreadsheets, Presentation, PDF tools, and AI-assisted features provide a familiar, streamlined workspace and an easy everyday migration path. Test macros, specialized add-ins, protected files, and Microsoft-only cloud integrations before replacing a critical Microsoft 365 workflow.

100% secure

AADSTS900561 Sign-In FAQs

Is AADSTS900561 caused by a wrong password?

Usually not. The code describes how the application called an identity endpoint. A bad password normally produces a different sign-in message.

Can I fix the error by changing GET to POST in the browser URL?

No. A browser address bar cannot safely reproduce the application’s token request. Restart from the app and let its authentication library create the request.

Why do Request ID and Correlation ID matter?

Together with the timestamp, they help an administrator locate the failed transaction in Microsoft Entra sign-in logs without exposing credentials.

What if Microsoft 365 signs in but one application still fails?

That strongly points to the application configuration or its saved session. Send the diagnostic IDs to the application owner and ask them to check the redirect URI and authentication flow.

Huda Qurayshi

Expert in office suites and technology with a strong background in writing. I specialize in reviewing public health topics, delivering insightful, accurate content for diverse audiences in tech.