How to Fix Azure Entra ID Redirect URI Mismatch Errors
Question details
Users are unable to log into an application because of a redirect URI mismatch error with Microsoft Entra ID.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Attempting to access and authenticate into a web application integrated with Microsoft Entra ID for Single Sign-On (SSO).
- Observed behavior
- The authentication process fails and returns an error (such as AADSTS50011) indicating that the application's callback address does not match any of the URIs configured in the Microsoft Entra ID app registration.
Ensure you have an active administrator account with access to the Azure portal, and verify the exact redirect URI (including http/https and trailing slashes) that your application is attempting to use during the login request.
Correct the Redirect URI in Microsoft Entra ID App Registration
Resolve the mismatch by adding or updating the application's callback URI within the Azure portal so it perfectly aligns with the requested address.
The AADSTS50011 error triggers as a security measure when the address an application wants to send an authenticated user back to (the redirect URI) is not explicitly whitelisted in the identity provider. Fixing this requires matching the strings exactly.
Navigate to portal.azure.com and sign in using your administrator credentials.
From the global search bar or the left-hand navigation menu, select 'Microsoft Entra ID' (formerly Azure Active Directory).
In the left-hand menu under the Manage section, click on 'App registrations' and select the specific application causing the error.
On the application's overview page, look at the left-hand menu again and click on 'Authentication'.
Under 'Platform configurations', locate the 'Redirect URIs' list. Click 'Add URI' (or edit an existing one) to input the exact callback address requested by your application. Ensure the scheme (https), domain, path, and any trailing slashes are a 1:1 match.
Click the 'Save' button at the bottom or top of the configuration pane to apply the new redirect URI. Allow a few minutes for the changes to propagate.

Discover WPS Office: A Lightweight and Free Office Suite
While resolving enterprise identity and Microsoft 365 configuration errors can be a complex task, finding the right desktop office software doesn't have to be. WPS Office provides a free, streamlined, and robust alternative for all your document needs without the enterprise overhead.

Frequently Asked Questions
What causes the AADSTS50011 redirect URI mismatch error?
This error occurs when the redirect URI (or reply URL) sent by the application during the authentication request does not exactly match any of the authorized redirect URIs registered for that specific application in the Microsoft Entra ID portal.
Do trailing slashes matter in Azure Entra ID redirect URIs?
Yes, Microsoft Entra ID evaluates redirect URIs using strict string matching. A URI with a trailing slash (e.g., https://app.example.com/callback/) is considered completely different from the same URI without a trailing slash (e.g., https://app.example.com/callback).
Can I use HTTP for my redirect URI in Microsoft Entra ID?
Microsoft Entra ID enforces HTTPS for all redirect URIs to ensure secure authentication flows. The only exception is for local development, where 'http://localhost' is permitted.
How long does it take for redirect URI changes to apply in Azure?
Changes made to application registration configurations, including redirect URIs, generally take effect within a couple of minutes. In rare cases of high latency, it may take up to 15 minutes to fully propagate.




