Exchange Online Management Powershell - AADSTS50013: Assertion failed signature validation

Jakob Jäger 0 Reputation points
2025-09-30T14:17:52.8+00:00

Hi,

I am trying to create a Complience Security Filter according to this documentation

https://learn.microsoft.com/en-us/purview/edisc-search-permission-filtering

But when trying to create the filter I get the following error in Powershell:

Write-ErrorMessage : AADSTS50013: Assertion failed signature validation. [Reason - Key was found, but use of the key
to verify the signature failed., Thumbprint of key used by client: '1D2DB76FB0E8ED371A5354682C7C2922ADB85588', Found
key 'Start=09/04/2025 05:46:45, End=09/04/2030 05:46:45', Please visit the Azure Portal, Graph Explorer or directly
use MS Graph to see configured keys for app Id '00000000-0000-0000-0000-000000000000'. Review the documentation at
https://docs.microsoft.com/en-us/graph/deployments to determine the corresponding service endpoint and
https://docs.microsoft.com/en-us/graph/api/application-get?view=graph-rest-1.0&tabs=http to build a query request URL,
such as 'https://graph.microsoft.com/beta/applications/00000000-0000-0000-0000-000000000000']. Trace ID:
b139778c-1768-4f2b-bdab-527f5ee81300 Correlation ID: 197ba374-5a83-4b0a-b0fb-7f33034f067f Timestamp: 2025-09-30
14:00:27Z
In C:\Users\jakob.jaeger\AppData\Local\Temp\tmpEXO_pdqfws42.elz\tmpEXO_pdqfws42.elz.psm1:1191 Zeichen:13
+             Write-ErrorMessage $ErrorObject
+             ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : NotSpecified: (:) [New-ComplianceSecurityFilter], Exception
    + FullyQualifiedErrorId : [RequestId=7918f211-33d8-cb65-b8b1-1e670975aa4c,TimeStamp=Tue, 30 Sep 2025 14:00:27 GMT]
   ,Write-ErrorMessage

Command I am using:

$dg = Get-DistributionGroup ediscoverysearchable
New-ComplianceSecurityFilter -FilterName "Filter Test" -Users "Role Test" -Filters "Mailbox_MemberOfGroup -eq '$($dg.DistinguishedName)'" -Action All

I also tried several different commands from the article with several different mailbox properties as filters, also tried with several different groups and users, instead of a role group

But I get the same error every time

The account used for Connect-ExchangeOnline and Connect-IPPSSession is ediscovery administrator and global administrator

What am I doing wrong?

best regards,

Jakob

Microsoft Security
Microsoft Security

A suite of security solutions designed to protect identities, devices, and data across organizations. Including Intune, Entra, Authenticator, Windows Autopilot, Microsoft Defender, and more, it offers advanced threat protection, compliance management, and secure access to resources.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.