Skip to content
RTFE_
Error library
Entra IDEntra IDKnown error

AADSTS7000222

The client secret expired

Credential expiration

What the error looks like

  • Error code
  • WHO โ€” identity
  • WHAT โ€” action
  • WHERE โ€” scope
  • Policy
  • Correlation / trace
ERROR: AADSTS7000222CODE: The provided client secret keys for app 'e5f6a7b8-0000-4000-8000-000000000005WHO' are expired. Visit the Azure portal to create new keys for your app: https://aka.ms/NewClientSecret, or consider using certificate credentials for added security: https://aka.ms/certCreds.
Trace ID: 33333333-4444-4555-8666-777777777777TRACE
Correlation ID: 44444444-5555-4666-8777-888888888888TRACE
Timestamp: 2026-03-14 07:02:11Z

What you told me

โ€œNothing changed and the pipeline broke.โ€

you ยท just now

Let's read it.

RTFE ยท seen

What it actually says

The client secret expired. Something did change: the date.

Azure outage? No. A credential reached its expiry date.

The fix

  1. 01Create a new client secret for the app (the app ID is in the error).
  2. 02Update every place that stores it: service connections, Key Vault, CI variables.
  3. 03Better: switch the service connection to workload identity federation โ€” no secret to expire.
Azure CLI โ€” rotate
az ad app credential reset \
  --id <application-id> \
  --display-name "rotated-<date>" \
  --years 1

Read it faster next time

Put secret expiry dates in a calendar. Or, better, stop using secrets.

Further reading

Open Microsoft Learn

Related errors