Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix CAA20003

CAA20003 and CAA82EE7 in Office: Token Broker Cannot Complete Authentication

10 min read Updated October 4, 2026 Outlook & Office Applications

Fix it now

CAA20003 is the one code in this family Microsoft documents, and it is not a local fault: ERROR_ADAL_SERVER_ERROR_INVALID_GRANT means the SAML token from the on-premises identity provider was not accepted by Entra ID. Start at the federation trust, not at the workstation.

Run these in an elevated Command Prompt, in order

dsregcmd /status
w32tm /query /status
w32tm /resync
  1. If the tenant is federated, check the federation service first: its token-signing certificate, its trust with Entra ID, and its own clock. CAA20003 means the token it issued was rejected.
  2. Check the clock and its source on the workstation as well. There is no /force parameter on w32tm /resync; adding one prints the usage block and does nothing.
  3. Check name resolution and reachability for the identity endpoints from the machine.
  4. Read the device state and single sign-on state sections of the dsregcmd output.
  5. Open Event Viewer and go to Applications and Services Logs, Microsoft, Windows, and read the Microsoft Entra operational log around the failure.

In that log, events 1006 and 1007 bracket a token acquisition attempt and 1007 carries the final error code. Event 1081 carries the server error code, 1084 the network sub-error and 1088 the WS-Trust fault.

If Office signs in silently after a reboot, you are done. The next section explains what the broker does and which of these codes are actually documented.

Why it happens

When an Office application needs a token it does not contact the identity service itself. It asks the Windows authentication broker, which holds the device’s credentials and knows how to obtain a token silently. The broker resolves endpoints, opens connections, uses the device key, and constructs a signed request. Any of that can fail locally, and when it does the tenant records nothing because nothing arrived.

That is the story usually told about CAA codes, and for some of them it is right. It is not right for the headline one. Microsoft publishes CAA20003 as ERROR_ADAL_SERVER_ERROR_INVALID_GRANT, described as the SAML token from the on-premises identity provider not being accepted by Entra ID. That is a server error. The request left the machine, reached Entra ID, and was rejected – which means a federated environment’s trust, its token-signing certificate or its own clock is where to look, not the user’s laptop.

The codes Microsoft does document in this range are the ADAL network errors, and they are worth knowing because they map cleanly onto ordinary network faults: 0xCAA82EE2 is a general network timeout, 0xCAA82EFD is a failure to connect to the identity endpoint, 0xCAA82EFE is a connection aborted, and 0xCAA82F8F is a TLS certificate from the server that could not be validated. CAA82EE7 sits in that same range and is not published, so treat it as a network-layer failure in the same family and diagnose it with the same tools.

CAA20004, CAA5004B, CAA20008 and CAA5001C have no published meanings at all. Neither does Event ID 1098. The events Microsoft actually documents in the Microsoft Entra operational log are 1006, 1007, 1022, 1081, 1084, 1088 and 1144, and in the User Device Registration log they are 201, 204, 220, 304, 305 and 307. If you have been told to look for 1098, you have been sent to an event that Microsoft does not describe.

The federation service’s token is being rejected

You have this one if CAA20003, a federated tenant, and the failure follows the user rather than the machine.

  1. Check the federation service’s token-signing certificate. An expired or newly rolled certificate that the tenant does not know about produces exactly this.
  2. Confirm the trust between the federation service and Entra ID is current, and re-establish it if the certificate has changed.
  3. Check the federation server’s own clock; a signed assertion outside its validity window is rejected on arrival.
  4. Test from a second machine to confirm the fault is not local before touching any workstation.

This is the cause that gets missed, because every article about CAA codes tells you to look at the workstation and this one is not there.

The broker cannot resolve or reach an identity endpoint

You have this one if CAA82EE7 or one of the documented 0xCAA82Exx values, and name resolution or the port test fails for the identity host names while ordinary browsing works.

  1. Check which DNS servers the machine is actually using.
  2. Test the same lookup against a known-good resolver to identify a filtering resolver.
  3. Check the proxy configuration and confirm the identity endpoints are allowed through without an authentication challenge.
  4. Flush the resolver cache and retest.

The machine clock is outside the accepted window

You have this one if A large offset or an unreachable time source, often with Kerberos problems alongside.

  1. Run w32tm /resync from an elevated prompt. Do not add /force; it is not a parameter of that command and the command will do nothing at all.
  2. If that fails, read the configured source and correct it; a domain member should follow the domain hierarchy.
  3. Restart the Windows Time service and resync again.
  4. Confirm the offset is small before retesting the application.

On virtual machines, host time synchronisation fighting the domain hierarchy gives a clock that drifts back after every correction. Turn one of them off rather than resyncing repeatedly.

The device has no usable registration to sign with

You have this one if The device state or single sign-on state reports as not joined, not registered, or failing device authentication.

  1. Confirm BitLocker recovery is escrowed before touching device state.
  2. For a hybrid-joined machine, confirm the on-premises device object is synchronising to the tenant.
  3. Rebuild the registration and reboot.
  4. Re-check both the device state and the sign-on state before testing Office.

A security agent is intercepting the broker’s traffic

You have this one if Failures track the presence of one endpoint product, and turning its encrypted-traffic scanning off on a test machine changes the outcome.

  1. Exclude the identity and Office endpoints from inspection in that product.
  2. If the licence tier exposes no exclusion mechanism, remove the test machine from the policy long enough to prove the cause.
  3. Re-enable protection with exclusions in place rather than leaving it off.
  4. Document the exclusion so it survives the next policy update.

Full reference

Where to look first

What you find What it points to
CAA20003 in a federated tenant The federation service’s token, certificate or clock
No matching entry in the tenant sign-in logs The request did not leave the machine
The clock is more than a few minutes out Time, before anything else
Identity endpoint names will not resolve DNS, a filtering resolver, or a captive network
A bad device or sign-on state in dsregcmd Device registration

Which of these codes are documented

Code Published? What Microsoft says
CAA20003 Yes The SAML token from the on-premises identity provider was not accepted by Entra ID
CAA82EE7 No Sits in the documented 0xCAA82Exx ADAL network range; no meaning published for this value
CAA20004 No No published meaning
CAA5004B No No published meaning
CAA20008 No No published meaning
CAA5001C No No published meaning
Event ID 1098 No Not among the events Microsoft documents in either log

The events that are documented

Log Event What it carries
Microsoft Entra operational 1006 The start of the token acquisition flow
Microsoft Entra operational 1007 The end of the flow and the final error code
Microsoft Entra operational 1022 The URL being accessed
Microsoft Entra operational 1081 The server error code from the authentication service
Microsoft Entra operational 1084 The sub-error code from the network stack
Microsoft Entra operational 1088 The server error and description from the WS-Trust endpoint
User Device Registration 204 The error code, HTTP status and message for a join failure
User Device Registration 305 Authentication error information with ADAL error codes

The ADAL network codes worth recognising

  • 0xCAA82EE2 – a general network timeout.
  • 0xCAA82EFD – the attempt to connect to the sign-in endpoint failed.
  • 0xCAA82EFE – the connection with the authorisation endpoint was aborted.
  • 0xCAA82F8F – the TLS certificate sent by the server could not be validated, which is what TLS inspection produces.
  • 0xCAA90017 – the authentication protocol is not WS-Trust, which points at the federation service’s configuration rather than the network.

When the tenant log really is empty

An empty sign-in log for the time of the failure is genuinely diagnostic for the network-layer codes, because nothing arrived. It is not diagnostic for CAA20003, where something did arrive and was refused. Check which code you have before concluding that the tenant has nothing to tell you, because the difference decides whether you spend the afternoon on a laptop or on a federation server.

Every code this article covers

Code What it points at Source
CAA20003 ERROR_ADAL_SERVER_ERROR_INVALID_GRANT: the SAML token from the on-premises identity provider was not accepted by Microsoft Entra ID Microsoft Learn
CAA82EE7 Sits in the documented 0xCAA82Exx range of ADAL network errors, but no meaning is published for this value not published by the vendor
CAA20004 Seen during broker token acquisition; no published meaning not published by the vendor
CAA5004B Seen during broker token acquisition; no published meaning not published by the vendor
CAA20008 Seen during broker token acquisition; no published meaning not published by the vendor
CAA5001C Seen during broker token acquisition; no published meaning not published by the vendor
Event ID 1098 Not among the events Microsoft documents in the Microsoft Entra operational log or the User Device Registration log not published by the vendor

Confirm the fix worked

  1. The time status shows a small offset and a source the machine can reach.
  2. The device and sign-on state report as expected.
  3. Office applications sign in without prompting after a reboot.
  4. Event 1007 in the operational log shows a successful token acquisition rather than an error code.
  5. For a federated tenant, a second user on a different machine also signs in cleanly.

Questions people ask about this

Is there really nothing in the tenant sign-in logs?

It depends on the code. For the network-layer failures, yes: the request never arrived, and an empty log is the diagnosis. For CAA20003 the request did arrive and was rejected, so the tenant has something to tell you and so does the federation service.

How accurate does the clock have to be?

Close. Authentication tolerates only a small window of drift, and once you are outside it nothing signs in. Treat any offset of more than a couple of minutes as the first thing to fix on the machine – but check the federation server’s clock too, because that one is easy to forget.

Which event should I look for?

1007 in the Microsoft Entra operational log, which carries the final error code for a token acquisition, and 1081 for the server error code. Event 1098 is widely recommended and is not among the events Microsoft documents.

Do I need a licence change to fix this?

No. Everything here is time, name resolution, device state, a local security agent or a federation trust. None of it is affected by which plan the tenant is on or which edition of Office is installed.

Is re-registering the device risky?

It is disruptive rather than dangerous, but check first. Make sure BitLocker recovery keys are escrowed somewhere reachable, and expect policies depending on device state to treat the machine as new until it has registered again.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error Excel #SPILL! and #CALC! Errors: Dynamic Arrays Blocked or Unsupported License Error Unlicensed Product 0xC004F017 in Word, Excel, Visio and Project: Activation Failed Free Fix Office Sign-in 0x80090016 Keyset Does Not Exist: Broken Identity and Device State Free Fix Outlook 0x800CCC0A Message Download Incomplete: Clear the Stuck Oversized Email
โ† Back to Knowledge Base