entra1-7 Exercise 3: Interpreting Extracts ========================================================= Source: Microsoft Learn error-code reference, sign-in log details, Conditional Access pages. Re-check the exact wording before quoting to a client. EXTRACT A: Service principal sign-in, Failure, 7000215, CA Not applied Likely cause: "Invalid client secret is provided." The application sent a credential that Entra does not recognise as valid. It is not reported as expired (that would be 7000222). Classic causes: the secret ID was used instead of the secret value, a typo, or an old/removed secret being used (Chapter 4). Belongs to: Credentials (Chapters 4 and 8). Confidence: Medium-high for "wrong secret"; medium for which wrong secret. Confirm with: The Certificates & secrets list (does a secret with the description we hold still exist?) and the audit log for removal or replacement; check what our system actually stores. EXTRACT B: Interactive, Failure, 53003, CA tab "Block outside UK" = Failure Likely cause: Conditional Access blocked token issuance (BlockedByConditionalAccess). Belongs to: Gate 3, conditions (Chapter 6). Confidence: High, because the CA tab names the policy. Confirm with: The Location tab/IP address of the failed sign-in versus the policy's named locations. The fix is for the client's security team to adjust the policy (for example, a travelling user or a new IP range), not to disable it. EXTRACT C: Non-interactive, Failure, 700082, last used 100 days ago Likely cause: The refresh token expired because of inactivity (Microsoft: an expected part of the token lifecycle). Belongs to: Token lifetimes (Chapter 4). Not an integration fault. Confidence: High. Confirm with: The user's previous sign-in date in the log, and the refresh token lifetimes. The user signs in again interactively. EXTRACT D: Interactive, Failure, 50011, redirect URI without trailing slash Likely cause: InvalidReplyTo: the redirect URI sent does not exactly match a reply URL registered for the app; the missing trailing slash is a classic cause. Belongs to: Configuration match (Chapters 3 and 5). Confidence: High if the logged URI differs from the registered one only by the slash. Confirm with: App registrations > Authentication list of redirect URIs versus the URI in the error. Someone with rights adds the exact URI, or our side is changed to match. WHY THIS WORKS AS AN ANSWER --- Each extract is read as who, how and what; the code is matched to one cause family; and the answer states what extra evidence would settle it, rather than treating the code as proof.