Why do I get an Azure.Identity.CredentialUnavailableException today, but it ran fine yesterday?

Falanga, Rod, DOH 1,255 Reputation points
2026-10-08T20:40:13.1233333+00:00

I've written an ASP.NET Minimal API in .NET 9. I was fixing a bug yesterday. Once I fixed the bug, I tested it and it worked fine.

Now, I want to work on another bug, so I brought the API project up in VS 2026 and tried run it. This time it failed on a line in the Program.cs file, whcih I didn't even touch yesterday. Here's the line:

builder.Configuration.AddAzureKeyVault(
    new Uri(vaultUri),
    new DefaultAzureCredential());

The error it produced said, in part:

Azure.Identity.CredentialUnavailableException HResult=0x80131500 Message=DefaultAzureCredential failed to retrieve a token from the included credentials. See the troubleshooting guide for more information. https://aka.ms/azsdk/net/identity/defaultazurecredential/troubleshoot

Then at the end of the lengthy error message, it said:

Inner Exception 1: System.AggregateException: 'Multiple exceptions were encountered while attempting to authenticate. (EnvironmentCredential authentication unavailable. Environment variables are not fully configured. See the troubleshooting guide for more information. [https://aka.ms/azsdk/net/identity/environmentcredential/troubleshoot](https://aka%5C.ms/azsdk/net/identity/environmentcredential/troubleshoot%5C)) (WorkloadIdentityCredential authentication unavailable. The workload options are not fully configured. See the troubleshooting guide for more information. [https://aka.ms/azsdk/net/identity/workloadidentitycredential/troubleshoot](https://aka%5C.ms/azsdk/net/identity/workloadidentitycredential/troubleshoot%5C)) (ManagedIdentityCredential authentication unavailable. No response received from the managed identity endpoint.) (Process "C:\Program Files (x86)\Microsoft Visual Studio\2019\Enterprise\Common7\IDE\Extensions\dmzzv0g5.xs4\TokenService\Microsoft.Asal.TokenService.exe" has failed with unexpected error: TS003: Error, TS004: Unable to get access token. 'AADSTS70043: The refresh token has expired or is invalid due to sign-in frequency checks by conditional access. The token was issued on 2026-10-01T19:07:28.9675360Z and the maximum allowed lifetime for this request is 604800. Trace ID: 2de28bdd-de3c-4957-9d76-3ff18d7f2100 Correlation ID: 93011fc4-1be4-4a49-9948-5e2e704ce80c Timestamp: 2026-10-08 20:18:03Z'.) (AzureCliCredential authentication failed: Azure CLI not installed) (AzurePowerShellCredential authentication failed: Az.Accounts module >= 2.2.0 is not installed.) (AzureDeveloperCliCredential authentication failed: Azure Developer CLI could not be found.)' Inner Exception 2: Azure.Identity.CredentialUnavailableException: 'EnvironmentCredential authentication unavailable. Environment variables are not fully configured. See the troubleshooting guide for more information. https://aka.ms/azsdk/net/identity/environmentcredential/troubleshoot'

I don't understand why this ran fine yesterday, but today it's a problem.

Azure Key Vault
Azure Key Vault

An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Atif Naseem Ahmed 160 Reputation points
    2026-10-08T21:49:18.76+00:00

    Hi Rod,

    Nothing in your code changed. The key line is at the end of the error:

    AADSTS70043: The refresh token has expired or is invalid due to sign-in frequency checks by conditional access. The token was issued on 2026-10-01 ... maximum allowed lifetime ... is 604800.

    DefaultAzureCredential is getting its token from your Visual Studio sign-in. Your organization has a Conditional Access policy that requires signing in again every 7 days (604,800 seconds). Your token was issued on Oct 1, so it expired between yesterday's run and today's.

    To fix it:

    1. In Visual Studio, go to Tools > Options > Azure Service Authentication > Account Selection and sign in again (or re-enter credentials under File > Account Settings).
    2. Run the API again.

    Note that the token service path in your error points to a Visual Studio 2019 install. If signing in again in VS 2026 doesn't help, sign in again in VS 2019 too, since that's the one the credential is using.

    To make it less fragile, install the Azure CLI and run az login. DefaultAzureCredential will then fall back to the CLI if the Visual Studio token expires. Either way, you'll need to sign in again every 7 days because of the policy.

    If this helps, please click "Accept Answer" so others can find it.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.