Entra IDEntra IDKnown error
AADSTS7000222
The client secret expired
Credential expiration
What the error looks like
- Error code
- WHO โ identity
- WHAT โ action
- WHERE โ scope
- Policy
- Correlation / trace
ERROR: AADSTS7000222CODE: The provided client secret keys for app 'e5f6a7b8-0000-4000-8000-000000000005WHO' are expired. Visit the Azure portal to create new keys for your app: https://aka.ms/NewClientSecret, or consider using certificate credentials for added security: https://aka.ms/certCreds.
Trace ID: 33333333-4444-4555-8666-777777777777TRACE
Correlation ID: 44444444-5555-4666-8777-888888888888TRACE
Timestamp: 2026-03-14 07:02:11ZWhat you told me
โNothing changed and the pipeline broke.โ
you ยท just now
Let's read it.
RTFE ยท seen
What it actually says
The client secret expired. Something did change: the date.
Azure outage? No. A credential reached its expiry date.
The fix
- 01Create a new client secret for the app (the app ID is in the error).
- 02Update every place that stores it: service connections, Key Vault, CI variables.
- 03Better: switch the service connection to workload identity federation โ no secret to expire.
az ad app credential reset \
--id <application-id> \
--display-name "rotated-<date>" \
--years 1Read it faster next time
Put secret expiry dates in a calendar. Or, better, stop using secrets.