how to fix signin issue. AADSTS501209: JWT signature is invalid [Reason - The key used is expired

Brenda Knight 0 Reputation points
2026-10-05T14:59:52.12+00:00

how to fix signin issue. AADSTS501209: JWT signature is invalid [Reason - The key used is expired.

I have an active Office 365 account which is current.

Microsoft 365 and Office | Subscription, account, billing | For business | Windows
0 comments No comments

2 answers

Sort by: Most helpful
  1. Brenda Knight 0 Reputation points
    2026-10-06T18:21:01.4866667+00:00

    I was unable to use any of your suggestions because I can't use either of the email addresses that I have for Office365 to get in. I keep getting a similar error message about the key having expired. I have tried to access AZURE and ENTRA from Google Chrome and also Microsoft EDGE. Both give me a similar message about having trouble signing me in.

    Here's a summary of what has happened:

    I am able to open outlook on my laptop, I get the error message saying it's having trouble signing me in.   I click to close that window and see that my email has not been loaded since the problem began on Oct 1st.   BUT, I can create new contacts, calendar items and use the other outlook features.   I can also use the word and excel apps from my office 365 account.  

    I believe the key that is being used when Outlook starts the process of downloading my email from an account that I have defined there, has become corrupted somehow. This feature of Outlook is the only part of the Outlook app that isn't working.

    As some point in this adventure, I needed to open a word doc and got the same issue that I had with Outlook. I then tried an excel doc with the same result. At that point, I thought the entire Outlook app was not working. But suddenly on Monday morning, I tested a word doc again and it opened fine, allowed me to make changes and then save. I had the same experience with an excel doc, but still no change in Outlook being able to deliver emails since 10/1.

    Another twist: this morning I got an email from Microsoft saying that my yearly subscription fee had been processed. On that email there's a link to manage accounts. I clicked there and am able to see my Microsoft account, details including that my subscription is now good until 10/6/2027

    Any help you can provide will be greatly appreciated.

    Was this answer helpful?

    0 comments No comments

  2. Roebe Ta 1,545 Reputation points Independent Advisor
    2026-10-05T15:12:16.43+00:00

    Hello @Brenda Knight,

    I hope you're doing well. 

    Based on my research, the error "AADSTS501209: JWT signature is invalid (key expired) " usually indicates that the JWT token is signed using an expired key (certificate or client secret) configured on the Microsoft Entra ID (Azure AD) app registration. 

    Once the signing key reaches its End date, Microsoft Entra ID will no longer accept tokens signed with it, resulting in the JWT signature validation failure. 

    To troubleshoot and resolve, you can try these steps: 

    1. Find your IT admin/Microsoft 365 admin to assist with this kind of issue.  

    If you haven’t yet reached out, here’s a helpful guide to locate your Microsoft 365 administrator: How do I find my Microsoft 365 admin? - Microsoft Support  

    2.Check credentials in the Azure Portal 

    • Sign in to Microsoft Entra ID at https://entra.microsoft.com using an administrator account. 
    • Navigate to Microsoft Entra ID > App registrations > All applications. 
    • Paste the Application (client) ID into the search box, or locate it directly in the Application (client) ID column. 

    User's image

    • Click on the app's Display name. 
    • Navigate to Certificates & secrets.  
    • Check and verify whether any credential has an End date in the past or matching the date shown in the error: 
      • Certificates under Certificates 
      • Client secrets under Client secrets

    User's image

     

    3. Rotate the expired credential (required) 

    If using a certificate 

    • Upload a new certificate 
    • Ensure the new certificate has a valid future expiration date 
    • Update the application/service to use the new certificate 

    User's image

     

    If using a client secret 

    • Create a new client secret 

    User's image

    • Copy the secret value immediately 
    • Update the application configuration with the new secret 

    The expired credential cannot be reused once its end date has passed. 

     

    4. (Optional) Verify via Microsoft Graph 

    You can also inspect configured credentials using Microsoft Graph using the instructions:  

    Review: 

    • keyCredentials > certificates 
    • passwordCredentials > client secrets 
    • Check the endDateTime values for expiration. 

    Note: Ensure you are using the correct Graph endpoint if the tenant is in a national cloud (GCC, Germany, China, etc.). 

    Once the credential is renewed and the application updated, authentication should succeed. 

    Please let me know if the issue persists. I'll be happy to assist further. 


    If the answer is helpful, please click "Yes, Accept Answer". If you have extra questions about this answer, please click "Comment".    

    Note: Please follow the steps in the forum documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.