AADSTS5000611: Microsoft sign-in fails behind a proxy
Signing in to a Microsoft work or school account in Chrome or Edge with Reach on shows:
AADSTS5000611: Symmetric Key Derivation Function version 'KDFV1' is invalid.
What it means
This isn't a Reach fault. Microsoft's device-based sign-in (Primary Refresh Token SSO on an Entra-joined Windows device) is bound to your device's real network path, so it breaks behind any proxy or VPN, not just Reach. Personal Microsoft accounts and browsers that don't use Windows PRT SSO aren't affected.
Fixes, in order
- Update Reach to 1.9.41 or newer. From that version the client routes Microsoft's login endpoints direct — bypassing the gateway — in normal regions, which resolves the error with nothing to configure. Check the version line in the tray and update from the download page.
- In mainland China and other restricted regions, use Firefox for the Microsoft sign-in. There, Microsoft's login servers are blocked locally, so Reach deliberately keeps routing them through the gateway — otherwise sign-in couldn't reach Microsoft at all. On an Entra-joined Windows device that means Chrome and Edge PRT sign-in can still fail. Firefox doesn't use Windows PRT SSO, so it signs in fine through the proxy.
- Switch Reach off for the sign-in, then back on. As a one-off workaround on an old version, sign in with the proxy off; the session token then works with Reach on.
Common questions
Is my account at risk?
No. The error is Microsoft refusing a device-bound token that arrived over an unexpected path. Nothing about your credentials is exposed.
Why does it only happen in Chrome and Edge?
Chrome and Edge on Windows participate in Windows' device SSO (PRT). Firefox — and Chrome/Edge on macOS and Linux — sign in with the ordinary web flow, which works through a proxy.
Does the same thing affect Google sign-in?
No. Google's sign-in isn't bound to the device network path.
Still stuck?
Get in touch with your Reach version, browser and region.