How to Fix Microsoft 365 Error AADSTS501204 Malformed JWT
Question details
The user needs to resolve the AADSTS501204 Malformed JWT sign-in error in Microsoft desktop applications after changing their password.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Attempting to sign in to installed Microsoft desktop applications after recently updating the account password.
- Observed behavior
- The AADSTS501204 Malformed JWT error blocks access to installed desktop applications, although signing in through a web browser continues to work normally.
Verify that your internet connection is stable and ensure you can successfully log in to your Microsoft account via a web browser to confirm your new password is correct before troubleshooting the desktop apps.
Clear Windows Credentials and Test on Another Device
Clearing cached passwords on your local device often resolves JWT token mismatches caused by a recent password change.
When you change your password, your desktop applications may still try to authenticate using an outdated or corrupted token stored locally. Removing these cached credentials forces the applications to request a fresh token.
Click the Start menu, type 'Credential Manager' into the search bar, and press Enter to open the utility.
Select 'Windows Credentials' and scroll down to the 'Generic Credentials' section. Look for any saved credentials containing 'MicrosoftOffice', 'msteams', or 'OneDrive'.
Click the down arrow next to each relevant credential and click 'Remove'. Confirm the deletion.
Restart your computer and try signing in to your Microsoft applications again. If the error persists, try signing into your account on a completely different computer to determine if the issue is specific to your local device.
Contact Your IT Administrator
If clearing credentials does not work, organizational policies or Azure AD configurations might be blocking access, requiring admin intervention.
Use WPS Office to Avoid Cloud Sign-In Interruptions
If Microsoft 365 sign-in errors are preventing you from accessing your urgent work, switch to WPS Office. It provides a lightweight, highly compatible, and free alternative that lets you view, edit, and create documents locally without being blocked by cloud authentication issues.
- 1. Download and Install: Visit the official WPS website to download the free installer, then run the setup file.
- 2. Open Your Files: Launch WPS Office and open your existing Microsoft Office files directly from your local drive.
- 3. Edit Offline: Continue editing and saving your documents normally without worrying about sign-in errors.

Frequently Asked Questions
What does the AADSTS501204 Malformed JWT error mean?
The AADSTS501204 error indicates that the JSON Web Token (JWT) used to authenticate your session is corrupted, malformed, or out of sync with Microsoft's servers. This often happens right after a user changes their account password.
Why can I still log into Microsoft 365 via my web browser?
Desktop applications rely on authentication tokens cached locally within Windows. When your password changes, this cache can become invalid. Web browsers, however, usually request a brand new token directly from Microsoft's servers each time you log in, bypassing the local cache issue.
How do I know if the error is caused by my device or my organization's policies?
The easiest way to check is to try signing into a desktop Microsoft application on a completely different computer using the same account. If the login is successful on the second computer, the issue is tied to your original device's cache. If it fails on both, it is likely an account or organizational policy issue.




