Issue: Connect-AzAccount authentication error while following AZ-104 Microsoft Learn exercise

Ammiel Jammiel 0 Reputation points
2026-10-02T12:10:34.7633333+00:00

Hello Microsoft Community,

I am currently preparing for the AZ-104: Microsoft Azure Administrator exam and following the Microsoft Learn exercise “Exercise – Create and deploy an Azure Resource Manager template.” I am completing the exercise using Visual Studio Code and Azure PowerShell.

As instructed in the exercise, I created and saved the ARM template JSON file and then ran the following command in the Visual Studio Code terminal:

Connect-AzAccount

The command opens the browser, and I am able to enter my Microsoft account credentials successfully. However, after authentication, instead of displaying the list of Azure subscriptions in the terminal as described in the exercise, I receive the following error:

Retrieving subscriptions for the selection...
WARNING: Unable to acquire token for tenant '85ca6447-617f-49ac-845d-d3e4ee3fefbc' with error 'Authentication failed 
against tenant 85ca6447-617f-49ac-845d-d3e4ee3fefbc. User interaction is required. This may be due to the conditional
access policy settings such as multi-factor authentication (MFA). If you need to access subscriptions in 
that tenant, please rerun 'Connect-AzAccount' with additional parameter '-TenantId 85ca6447-617f-49ac-845d-d3e4ee3fefbc'.'

WARNING: Unable to acquire token for tenant 'organizations' with 'SharedTokenCacheCredential authentication failed: '

WARNING: Please run 'Connect-AzAccount -DeviceCode' if browser is not supported in this session.

Connect-AzAccount : SharedTokenCacheCredential authentication failed:
At line:1 char:1
+ Connect-AzAccount
+ ~~~~~~~~~~~~~~~~~
    + CategoryInfo          : CloseError: (:) [Connect-AzAccount], AuthenticationFailedException
    + FullyQualifiedErrorId : Microsoft.Azure.Commands.Profile.ConnectAzureRmAccountCommand

Expected result

According to the Microsoft Learn exercise, after signing in, I should see a list of the subscriptions associated with my account in the Visual Studio Code terminal, with my default subscription marked with an asterisk (*).

Actual result

Authentication appears to complete successfully in the browser, but Azure PowerShell cannot retrieve my subscriptions and returns the authentication error shown above.

Environment

  • Exam: AZ-104 Microsoft Azure Administrator
  • Exercise: Create and deploy an Azure Resource Manager template
  • Operating system: Windows
  • IDE: Visual Studio Code
  • Shell: PowerShell
  • Command: Connect-AzAccount
  • Authentication: Microsoft account with MFA enabled
  • Azure: I have an Azure subscription associated with the account

Question

Could someone please advise what is causing this authentication issue and the recommended way to resolve it?

In particular, should I:

  1. Run Connect-AzAccount -TenantId <tenant-id> as suggested by the error?
  2. Use Connect-AzAccount -DeviceCode instead?
  3. Check or update any Azure/Entra ID Conditional Access or MFA settings?
  4. Use another authentication method for completing this Microsoft Learn AZ-104 exercise?

I would appreciate any guidance on the correct approach, particularly one that follows the Microsoft Learn exercise and does not cause issues with my Azure subscription or tenant configuration.

Thank you.Hello Microsoft Community,

I am currently preparing for the AZ-104: Microsoft Azure Administrator exam and following the Microsoft Learn exercise “Exercise – Create and deploy an Azure Resource Manager template.” I am completing the exercise using Visual Studio Code and Azure PowerShell.

As instructed in the exercise, I created and saved the ARM template JSON file and then ran the following command in the Visual Studio Code terminal:

Connect-AzAccount

The command opens the browser, and I am able to enter my Microsoft account credentials successfully. However, after authentication, instead of displaying the list of Azure subscriptions in the terminal as described in the exercise, I receive the following error:

Retrieving subscriptions for the selection...
WARNING: Unable to acquire token for tenant '85ca6447-617f-49ac-845d-d3e4ee3fefbc' with error 'Authentication failed 
against tenant 85ca6447-617f-49ac-845d-d3e4ee3fefbc. User interaction is required. This may be due to the conditional
access policy settings such as multi-factor authentication (MFA). If you need to access subscriptions in 
that tenant, please rerun 'Connect-AzAccount' with additional parameter '-TenantId 85ca6447-617f-49ac-845d-d3e4ee3fefbc'.'

WARNING: Unable to acquire token for tenant 'organizations' with 'SharedTokenCacheCredential authentication failed: '

WARNING: Please run 'Connect-AzAccount -DeviceCode' if browser is not supported in this session.

Connect-AzAccount : SharedTokenCacheCredential authentication failed:
At line:1 char:1
+ Connect-AzAccount
+ ~~~~~~~~~~~~~~~~~
    + CategoryInfo          : CloseError: (:) 

Expected result

According to the Microsoft Learn exercise, after signing in, I should see a list of the subscriptions associated with my account in the Visual Studio Code terminal, with my default subscription marked with an asterisk (*).

Actual result

Authentication appears to complete successfully in the browser, but Azure PowerShell cannot retrieve my subscriptions and returns the authentication error shown above.

Environment

  • Exam: AZ-104 Microsoft Azure Administrator
  • Exercise: Create and deploy an Azure Resource Manager template
  • Operating system: Windows
  • IDE: Visual Studio Code
  • Shell: PowerShell
  • Command: Connect-AzAccount
  • Authentication: Microsoft account with MFA enabled
  • Azure: I have an Azure subscription associated with the account

Question

Could someone please advise what is causing this authentication issue and the recommended way to resolve it?

In particular, should I:

  1. Run Connect-AzAccount -TenantId <tenant-id> as suggested by the error?
  2. Use Connect-AzAccount -DeviceCode instead?
  3. Check or update any Azure/Entra ID Conditional Access or MFA settings?
  4. Use another authentication method for completing this Microsoft Learn AZ-104 exercise?

I would appreciate any guidance on the correct approach, particularly one that follows the Microsoft Learn exercise and does not cause issues with my Azure subscription or tenant configuration.

Thank you.

Azure | Azure Training
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-10-02T12:10:53.99+00:00

    The failure is consistent with a tenant selection and MFA/Conditional Access issue during Azure PowerShell sign-in.

    The supported fixes are:

    1. Sign in to the correct tenant explicitly Azure PowerShell can try the first tenant it finds during login. If that tenant requires MFA or has different access requirements, authentication can fail even though browser sign-in succeeded. Run:
         Connect-AzAccount -TenantId 85ca6447-617f-49ac-845d-d3e4ee3fefbc
      
      This is the recommended first step for the warning shown in the terminal.
    2. Use an MFA-compatible interactive sign-in method Password-based sign-in does not support MFA. Interactive sign-in does. If Conditional Access requires MFA for the operation, use interactive authentication and complete MFA when prompted. If Azure PowerShell returns a claims challenge, run:
         Connect-AzAccount -Tenant (Get-AzContext).Tenant.Id -ClaimsChallenge "<claims-challenge-token>"
      
      Another documented option is to have MFA enforced at sign-in by the Azure administrator so the session already satisfies Conditional Access.
    3. Use device code only if browser-based sign-in is unavailable or fails to open Device code is not the primary fix for the tenant warning. It is used when Web Account Manager or the browser is unavailable or fails.
         Connect-AzAccount -UseDeviceAuthentication
      
      Since the browser already opens and sign-in completes, the tenant-specific sign-in is the more relevant fix.
    4. Check Az PowerShell module version Older versions can show the less-informative SharedTokenCacheCredential authentication unavailable style of error. More recent versions provide clearer MFA/policy details. The documented versions that improve this are:
      • Az 14.3.0 or later
      • Az.Accounts 5.2.0 or later

    For the Microsoft Learn exercise, the best path is:

    1. Update Az/Az.Accounts if needed.
    2. Retry sign-in with the tenant specified:
         Connect-AzAccount -TenantId 85ca6447-617f-49ac-845d-d3e4ee3fefbc
      
    3. If Conditional Access still requires MFA for the operation, complete interactive MFA or use the claims challenge command if Azure PowerShell returns one.
    4. Use device authentication only if browser-based sign-in is not working in the session.

    This approach does not change the subscription or tenant configuration by itself; it only makes Azure PowerShell authenticate against the intended tenant using an MFA-compatible flow.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.