# Invalid\_user\_credentials error with Microsoft Active Directory as IdP

**URL:** <https://forum.keycloak.org/t/invalid-user-credentials-error-with-microsoft-active-directory-as-idp/24024>\
**Category:** Securing applications\
**Tags:** authentication, user-federation, oidc, saml\
**Created:** [January 10, 2024, 5:04pm UTC](https://forum.keycloak.org/t/invalid-user-credentials-error-with-microsoft-active-directory-as-idp/24024 "2024-01-10T17:04:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![gah1289](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/gah1289/32/9556_2.png) [@gah1289](https://forum.keycloak.org/u/gah1289)\
**Post date:** [January 10, 2024, 5:04pm UTC](https://forum.keycloak.org/t/invalid-user-credentials-error-with-microsoft-active-directory-as-idp/24024/1 "2024-01-10T17:04:51Z")

</div>

I have an issue where customers are using Microsoft Active Directory + Okta and receiving an invalid username/password error in Keycloak after providing the correct password.

Flow: User successfully logs into Microsoft and is redirected to Okta homepage → User clicks on app → Invalid username/password error comes from Keycloak.

Workaround: Manually unlink and re-link idp for user in Keycloak.

We’re seeing this occur when a customer has mixed casing in their email address (i.e. [Testuser@Test.com](mailto:Testuser@Test.com)). All affected users are using Microsoft Active Directory. The problem is I can’t reproduce it. See logs below, note the following:

- userId=null
- auth\_method=openid-connect (the idp in keycloak is set to SAML)
- identity\_provider\_identity=\<USER\_EMAIL\>

```auto
log:2024-01-03 05:52:28,312 WARN [org.keycloak.events] (executor-thread-12481) type=IDENTITY_PROVIDER_FIRST_LOGIN_ERROR, realmId=<REALM_ID>, clientId=<CLIENT_ID>, userId=null, ipAddress=<IP_ADDRESS>, error=invalid_user_credentials, identity_provider=<IDENTITY_PROVIDER>, auth_method=openid-connect, redirect_uri=<REDIRECT_URI>, identity_provider_identity=<USER_EMAIL>, code_id=<UUID>, authSessionParentId=<UUID>, authSessionTabId=<TAB_ID> time:Jan 3, 2024 @ 00:52:28.312 stream:stdout logtag:F kubernetes.labels.app.kubernetes.io/name:sso

```

Has anyone been able to solve this? I’ve found similar posts online but haven’t found a working solution.

- [https://stackoverflow.com/questions/65920859/second-login-with-remote-idp-through-keycloak-fails-invalid-username-or-passwo](https://stackoverflow.com/questions/65920859/second-login-with-remote-idp-through-keycloak-fails-invalid-username-or-passwo)

---

<div class="post-metadata">

**Author:** ![noraab](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/noraab/32/12021_2.png) [@noraab](https://forum.keycloak.org/u/noraab)\
**Post date:** [March 11, 2025, 11:12pm UTC](https://forum.keycloak.org/t/invalid-user-credentials-error-with-microsoft-active-directory-as-idp/24024/2 "2025-03-11T23:12:08Z")

</div>

Hi @gah1289,

in case it is still relevant: I experienced the same issue. But in the end I found that it has nothing to do with mixed case. In my case, the first broker login flow had the wrong order. It first had `Automatically set existing user` followed by `Create user if unique` - but it should be the other way around:

 ![image](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/f/f80b4acfb267d5e1d92649d8e7c352f0868f9cd5.png)
