AADSTS900561 means a Microsoft identity endpoint received the wrong type of web request. It often appears when a browser opens an authentication or token endpoint directly, a saved link is stale, or an application builds an incorrect sign-in redirect. The request and correlation IDs are diagnostic values, not passwords or activation codes.
What AADSTS900561 Means During Microsoft Sign-In
Do not repeatedly refresh the error URL or edit its parameters. Record the Request ID, Correlation ID, timestamp, application name, and the page where sign-in started; remove tenant names or other sensitive details before sharing them publicly.
Restart the Authentication Flow from the Correct Entry Point

- Close the error tab and start again from the application’s normal sign-in button or an official Microsoft 365 portal. Never bookmark the long authentication endpoint.
- Open a private browser window and retry. If it works, clear cookies for the application and Microsoft sign-in domains in the regular browser, then sign in again.
- Try the same account at m365.cloud.microsoft. If Microsoft 365 works but the third-party or internal app fails, the application flow is the likely cause.
- Give the administrator the Request ID, Correlation ID, timestamp, and app name. In Microsoft Entra admin center, review the matching sign-in log and verify that the app registration uses an exact, approved redirect URI and a supported authorization flow.
Follow the relevant official guidance in Microsoft’s documentation, and verify the result before changing a wider deployment or replacing the original file.
Check the App Registration When the Error Persists
Users cannot repair an application registration from the error page. For a company-built app, the developer should verify that authorization requests and token exchanges use the documented methods rather than sending a browser GET request to a POST-only endpoint.
Use WPS Office Without Bypassing Microsoft Sign-In
WPS Office cannot repair a Microsoft Entra application registration or bypass its authentication flow. It remains a free, lightweight Microsoft Office-compatible alternative for local DOCX, XLSX, PPTX, and PDF work.

Writer, Spreadsheets, Presentation, PDF tools, and AI-assisted features provide a familiar, streamlined workspace and an easy everyday migration path. Test macros, specialized add-ins, protected files, and Microsoft-only cloud integrations before replacing a critical Microsoft 365 workflow.
AADSTS900561 Sign-In FAQs
Is AADSTS900561 caused by a wrong password?
Usually not. The code describes how the application called an identity endpoint. A bad password normally produces a different sign-in message.
Can I fix the error by changing GET to POST in the browser URL?
No. A browser address bar cannot safely reproduce the application’s token request. Restart from the app and let its authentication library create the request.
Why do Request ID and Correlation ID matter?
Together with the timestamp, they help an administrator locate the failed transaction in Microsoft Entra sign-in logs without exposing credentials.
What if Microsoft 365 signs in but one application still fails?
That strongly points to the application configuration or its saved session. Send the diagnostic IDs to the application owner and ask them to check the redirect URI and authentication flow.




