AADSTS50078: MFA Expired due to Admin Policy

AADSTS50173 - The provided grant has expired due to it being revoked

Error: AADSTS50173 - The provided grant has expired due to it being revoked

This error usually appears when a delegated admin account’s MFA configuration has changed — for example, when MFA was turned off, reset, or conditional access was newly applied, or a password was changed or reset.

Cause: Microsoft invalidates the session if MFA was reset or modified, requiring a fresh token via re-consent.

Resolution

Re-consent the delegated admin account in Sync 365 to refresh the token:

  1. Login to Sync 365
  2. Go to Company → Delegated admin tab
  3. Verify which account is currently active (do not delete it)
  4. Click Add → Grant partner center consent
  5. Log in using the current delegated admin account
  6. Ensure you’re prompted for MFA — this is required for Partner Center token validation

This should reissue the refresh token and restore access to the customer tenant.