Free tools Windows power users keep installed
One-click scans. No signup required.
Start with the failed sign-in event, then identify where the flow stopped: at identity-provider authentication, during MFA, or after the application received a SAML response or OIDC token. The error location and protocol evidence usually narrow the cause faster than changing settings at random.
Start with the failed sign-in event
Reproduce one affected login if possible. Record the timestamp and time zone, user identifier, application, correlation or request ID, exact error code and message, failure reason, and additional details. Keep the record tied to one event; repeated attempts can produce different IDs and failure causes.
In Microsoft Entra, use Sign-in logs and filter by user or application and failure status. Microsoft documents Reports Reader as the least-privileged role for accessing activity logs, though role requirements can depend on tenant setup and may change. If the event details do not explain the failure, use Sign-in diagnostics with the user or application and the event’s correlation or request ID and time. The diagnostic can identify scenarios such as incorrect credentials, MFA proof-up, per-user MFA, or other sign-in issues.
Locate the stage where the flow fails
| What the user sees | Likely failure location | Evidence to inspect |
|---|---|---|
| An error on the identity provider’s sign-in page | Before the identity provider issues a response or token | Event failure reason; for SAML, the incoming request’s destination, issuer, and AssertionConsumerServiceURL |
| Authentication succeeds, then the application shows an error | The application may have rejected an issued SAML response or OIDC token | Application logs and sanitized response/token details; compare identity, claims, signature, and validation expectations |
| An MFA prompt loops, is abandoned, or never completes | MFA interruption, incomplete initial setup, or a policy requirement | Sign-in event’s failure reason and additional details, plus diagnostic results |
| An OIDC callback or protocol error appears | Authorization request or callback configuration, or application-side token validation | Actual redirect URI, application registration, provider metadata, and the application’s validation error |
These patterns are clues, not proof. Confirm the location from the event and application logs before changing configuration.
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Troubleshoot SAML request and response failures
If the identity provider rejects the request
Capture the SAML request with the identity platform’s test or diagnostic feature, or another approved inspection method. Compare the request against the identity provider and service provider configuration:
- Destination: does it match the identity provider’s SAML single sign-on service URL?
- Issuer: does it match the application identifier configured for the service provider?
- AssertionConsumerServiceURL: does it point to the expected application endpoint?
In Microsoft Entra integrations, AADSTS75005 means the SAML request is not a supported or valid SAML protocol message. Missing required fields or request encoding can be causes; capture the request and confirm protocol compatibility with the application vendor rather than assuming the identity provider or app is at fault.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
If the application rejects the response
Inspect the response and compare it with the service provider’s documented requirements. Check whether the NameID value and format identify the user as expected, whether required attributes or claims are present, and whether the signature and signing certificate meet the application’s expectations. Missing attributes, an unrecognized identity value, or a signature-method mismatch can prevent the application from accepting an otherwise successful sign-in.
For Microsoft Entra SAML applications, configuration items to compare include the app Identifier, Reply URL, metadata XML or certificate, and claims mapping. Entra’s application settings provide the metadata XML in the SAML signing certificate section. Console labels and paths are Microsoft-specific and may change; do not apply them to another identity provider.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Troubleshoot OIDC redirect and token errors
Check the authorization request and redirect URI
Compare the application ID, expected tenant or authority, requested openid scope, and redirect URI in the actual authorization request with the application registration. The redirect URI must match one registered for the application; check the complete URI, including scheme, host, path, and any trailing slash. The request may URL-encode the URI, so compare its decoded value with the registered value as well.
Microsoft Entra documents AADSTS50011 for a redirect mismatch and uses the message “The redirect URI specified in the request does not match.” Treat that code as Microsoft-specific, not as a universal OIDC error.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
If the application receives a token but rejects it
Use the application’s token-validation error to identify which check failed. Validate the signature and claims against the application’s requirements, using the provider’s OpenID configuration document and signing-key metadata. Relying on current metadata helps an application handle signing-key rotation; a manually pinned obsolete key can cause validation failures. Validation requirements differ by client type and architecture, so follow the identity platform and application’s guidance rather than applying one checklist indiscriminately.
Separate consent failures from callback failures
If the response points to consent, check whether the application requested a resource or permission that still needs user or administrator consent. A similar-looking error in a SAML integration can have a different configuration cause, so identify the protocol and inspect the corresponding event details before changing permissions.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Check MFA as its own failure path
Do not assume that an MFA-related failure means the second factor itself is broken. Check whether the user completed the prompt, whether initial MFA setup was interrupted or incomplete, and whether a Conditional Access or per-user setting required the challenge.
In Microsoft Entra, error 500121 is documented for an incomplete MFA prompt. Sign-in diagnostics can distinguish an interrupted first-time setup (“proofup”) from MFA requirements imposed by policy or per-user settings and provide remediation details. Follow the identified cause and your organization’s policy; the exact policy design is tenant-specific.
Compare evidence by protocol and failure location
| Investigation | Most useful evidence | Typical checks |
|---|---|---|
| SAML request rejected by identity provider | Request and identity-provider event | Destination, issuer, AssertionConsumerServiceURL, required fields, and request encoding |
| SAML response rejected by application | Response and application-side error | NameID, claims, signing certificate, and signature expectations |
| OIDC authorization or callback failure | Authorization request and sign-in event | Application ID, authority, openid scope, and registered redirect URI |
| OIDC token rejected by application | Token-validation error and provider metadata | Signature, current signing keys, and required claims |
| MFA interruption | Sign-in details and diagnostic result | Prompt completion, initial setup, and policy source |
Escalate with a safe evidence bundle
If the cause remains unclear, send the identity-provider or application support team the timestamp and time zone, correlation or request ID, exact error and failure details, and the relevant configuration values. Include sanitized SAML request/response material or token-validation details only when appropriate and through the vendor’s secure support channel. Never include passwords, client secrets, or live bearer tokens in a ticket. Microsoft identifies the correlation ID and timestamp as useful when opening a support case; other vendors may request different evidence.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors




