[Follow-up] AADSTS9002325 persists after all recommended fixes — new Web-only app registration, Standard plan, weeks of troubleshooting exhausted

2026-06-29T06:13:25.62+00:00

We are posting this as a follow-up to our two previous questions on this forum:

Steelcraft Group is an Australian manufacturing business running Microsoft 365 and Azure, and we have been blocked by the AADSTS9002325 error on Azure Static Web Apps Easy Auth for several weeks. This is a significant roadblock to our internal IT roadmap.

We would like to acknowledge Sumesh Ramasamy for his detailed response on our second post. We followed his recommendation to validate the app registration at the manifest level and created a brand new Web-only app registration with no SPA configuration whatsoever, as he specifically suggested. We have also been working with Microsoft support engineer Sridevi Machavarapu, to whom we provided correlation IDs from failed sign-in logs.

We would also note a pattern emerging across both posts -- initial responses are provided promptly, but follow-up engagement does not occur, leaving us without a resolution path.

To summarise what we have tried to date:

  • Moved the SWA callback URI from the SPA platform to the Web platform
  • Removed all SPA redirect URIs from the app registration, including localhost entries
  • Confirmed the manifest has no SPA entries and Allow public client flows is set to No
  • Tested both v1 and v2.0 issuer endpoints with requestedAccessTokenVersion set to null, 1, and 2 — all combinations produce the same error
  • Created a brand new Web-only app registration with no SPA configuration whatsoever, as specifically recommended by Sumesh
  • Verified the SWA is on the Standard plan with managed identity enabled and Key Vault integration configured correctly
  • Opened a Microsoft support ticket with Sridevi Machavarapu and provided correlation IDs from failed sign-in logs

Despite all of this, the error persists. We have followed every recommendation from Microsoft documentation and from technicians on this forum, and we are no closer to a resolution.

This issue has consumed a disproportionate amount of time and resources for our IT team. We would expect a company of Microsoft's scale to provide clearer documentation, faster support responses, and better outcomes for customers who are actively investing in the Azure platform.

We are asking for:

  1. A definitive explanation of why AADSTS9002325 persists on a clean Web-only app registration with no SPA configuration
  2. A confirmed working configuration for Azure Static Web Apps Easy Auth with Entra ID on the Standard plan
  3. Escalation of our support ticket if the above cannot be resolved through this forum

We appreciate any assistance the community or Microsoft engineers can provide.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.