Setting up Microsoft PIN Reset Service - AADSTS500113: No reply address is registered for the application.

Ronald 5 Reputation points
2024-07-24T00:46:03.0033333+00:00

Hi All

I am trying to follow this article on resetting Pin

https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/pin-reset?tabs=intune#how-nondestructive-pin-reset-works

When trying to log into the Microsoft Reset Pin Production Portal I get this message

What do I need to do in Azure as I cant find any instructions on what to do?

I see I need to use App Registration to setup some kind of Redirection URL but I have no idea what to set it?

At the moment there is nothing in "App Registration" in Azure

User's image

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,189 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,982 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,617 questions
{count} vote

1 answer

Sort by: Most helpful
  1. Raja Pothuraju 1,940 Reputation points Microsoft Vendor
    2024-07-25T14:50:53.3866667+00:00

    Hello @Ronald,

    Thank you for posting your query on Microsoft Q&A.

    As you mentioned, you are attempting to enable the Microsoft PIN reset service for your users to recover a forgotten Windows Hello for Business PIN. You are encountering the error message "AADSTS500113: No reply address is registered for the application" when logging into the Microsoft Reset Pin Production Portal.

    This error message is expected after granting admin consent to the Microsoft Pin Reset Client Production application. Please refer to the screenshot below to understand the process when registering the applications:

    When you go to the Microsoft PIN Reset Service Production website, and sign in with Global administrator or at least an Application Administrator user, you will be prompted to consent to the application with the page shown below.

    User's image

    After clicking "Accept" and completing the consent for the application, you will be redirected to https://login.microsoftonline.com/common/Consent/Set with the mentioned error message. You do not need to take any action on this error; it is expected behavior following the consent acceptance, as outlined in the documentation.User's image To confirm that the two PIN Reset service principals are registered in your tenant, follow these steps:

    1. Sign in to the Microsoft Entra Manager admin center
    2. Select Microsoft Entra ID > Applications > Enterprise applications
    3. Search by application name "Microsoft PIN" and verify that both Microsoft Pin Reset Service Production and Microsoft Pin Reset Client Production are in the list PIN reset service permissions page.

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

    Thanks,
    Raja Pothuraju.

    0 comments No comments