Skip to main content

204001 - Failed to Log In to Azure

Agent error code #204001 indicates that the service principal on the knoc failed to authenticate with Entra ID. The agent signs in with the service principal before it manages NSG rules, and Entra ID refused the credentials.

Common causes include:

  • The client ID, client secret or tenant ID on the knoc is wrong
  • The client secret has expired
  • The service principal was deleted or disabled
  • The agent host cannot reach Entra ID (login.microsoftonline.com)
  • Conditional Access is blocking the sign-in

Steps to Resolve

Re-enter the Service Principal Credentials

  1. In the Knocknoc admin interface, open the backend configuration for the affected knoc
  2. Re-enter the client ID, client secret and tenant ID, taking care not to include surrounding whitespace
  3. Save and retry the grant

Check the Secret Has Not Expired

Client secrets have a fixed lifetime and Azure does not warn the caller in advance.

  1. In the Azure portal, go to Microsoft Entra ID > App registrations > your app > Certificates & secrets
  2. Check the expiry of the secret in use
  3. If it has passed, create a new secret and update the knoc

Check the Credentials by Hand

From a machine with the Azure CLI, sign in with the same service principal to see the underlying error:

az login --service-principal \
  --username <client-id> --password <client-secret> --tenant <tenant-id>

Check Conditional Access

A Conditional Access policy that requires multi-factor authentication or a compliant device blocks a service principal sign-in. Check the Entra ID sign-in logs for the application and look for a policy-driven failure.