"The client secret may have expired"

Why CloudCard can't sign in to Microsoft Entra ID, and how to create a new client secret and update your connection.

PlansProPremiumCompare plans

ForAdmins

On this page

You’ll see this message when CloudCard can’t connect to your Microsoft Entra ID directory:

“CloudCard could not sign in to Microsoft Entra ID with the stored credentials. The client secret may have expired.”

It appears on the Groups and roles page and in sync results. Until it’s fixed, CloudCard stops syncing users from your directory. If your staff sign in with Microsoft, that may stop working too, so they should use their passwords.

Why it happens

CloudCard signs in to Microsoft with the app registration details you entered during setup. The message appears when Microsoft rejects them. The most common cause is an expired client secret, but it also happens when:

  • the secret’s Secret ID was pasted instead of its Value
  • the client ID or tenant ID is wrong
  • the app registration was deleted in Azure

Check the expiry date

  1. In the left menu, click Team Members.
  2. Click Add Users, then Microsoft Entra ID import. The Microsoft Entra ID page opens.

The page shows when the client secret expires, for example “Secret expires in 12 days” or “Secret expired”. If it has expired, a banner says “This connection has stopped working.” Nothing in CloudCard has been deleted.

CloudCard emails reminders 30, 14, 7 and 1 days before the expiry date you entered. The date is based on when you saved the secret and the period you chose, so check the real date in Azure too.

Create a new secret and update CloudCard

  1. On the Microsoft Entra ID page, click Connection setup.
  2. Click Azure Portal (or go straight to App registrations), and open the CloudCard app registration.
  3. Under Certificates & secrets, create a new client secret. CloudCard recommends an expiry of 12 months.
  4. Copy the secret’s Value straight away. Azure only shows it once.
  5. Back in CloudCard, paste it into Client secret value.
  6. Set Client secret expires in to match the expiry you chose in Azure.
  7. Click Update.

CloudCard tests the new details when you save. You’ll see “Credentials updated”, and syncing starts working again. If you see “Invalid credentials”, check you copied the Value and not the Secret ID, and that the client and tenant IDs are correct.

To check straight away, click Sync now on the Microsoft Entra ID page.

See Renew your Entra ID client secret for more detail.

Still not connecting? Contact support.

Still stuck?

Send us a message and we'll know which article you were reading. Or email [email protected].

Contact support