Troubleshooting Tip: Failed to get Microsoft Entra Groups due to client secret expiration
Description | This article describes how to troubleshoot the issue where FortiSASE fails to get Microsoft Entra ID Groups due to client secret expiration. |
Scope | FortiSASE. |
Solution | By connecting a Microsoft Entra ID domain to FortiSASE, the synchronized Entra groups can be used for purposes such as Endpoint Group assignment. In this scenario, when Endpoint Groups are not assigned as intended according to the Entra groups, it is necessary to verify whether the domain sync with Entra ID is working correctly. Issue: For FortiSASE to synchronize information from Microsoft Entra ID, a valid client secret must exist on Entra ID, and the same client secret must be applied on the FortiSASE side. When the client secret expires on the Entra ID side, the group synchronization silently stops working, and changes made on Entra ID are no longer reflected on FortiSASE. The following symptoms may indicate that the client's secret has expired:
To collect a HAR file on a Windows device, press the F12 key in a major web browser such as Google Chrome or Microsoft Edge. Name: domain-stats -> Response: ![]()
Select the target domain, select 'Edit', then select 'Update' without changing anything. ![]() ![]()
Go to Microsoft Entra ID -> Monitoring -> Sign-in logs -> Service principal sign-ins. Select a log entry with the Status 'Failure'. If the client secret has expired, the following error appears in the 'Failure reason' field: ![]()
Therefore, be sure to keep track of its expiration date and renew the client secret before it expires. Related article: Technical Tip: FortiSASE Failed to get Microsoft Entra Groups |




