
You have just entered your username on the portal courriel.aphp.fr, the page is loading, and then an error message appears. The instinct is often to quickly retype the password multiple times. This instinct worsens the situation. Understanding why the connection to the AP-HP messaging fails can save time and prevent a potentially lengthy account lockout.
Account locked after several attempts: the most common trap
The security policies of the hospital information system have tightened. The quality and safety standards updated by the HAS now require enhanced traceability of professional connections and widespread strong authentication. In practice, the system detects repeated or suspicious login attempts.
Three or four consecutive incorrect passwords are enough to trigger an automatic account lockout. The portal does not always clearly inform you: you may see a simple message “incorrect username or password” when the issue is no longer the password, but the lockout.
Before trying again, wait a few minutes. If the connection remains impossible, contact IT support. From inside an AP-HP hospital, dial *75. From outside, the number is 01 40 27 40 00. You can also write to [email protected]. A complete guide on AP-HP remote diagnostics on Hebdo Linux details the most common error codes and their step-by-step solutions.
Strong authentication error: when Microsoft Authenticator blocks access
Have you ever validated your connection on the web portal, only to see a second screen asking for a code or approval on your phone? This is multi-factor authentication (MFA), which has become mandatory for AP-HP messaging.

The application used is Microsoft Authenticator. It generates a temporary code or sends a push notification. The error occurs in several specific cases:
- The phone is not connected to the internet (neither Wi-Fi nor mobile data). Without a network, the push notification never arrives, and the approval time expires.
- The phone’s time is off, even by a few minutes. Temporary codes (OTPs) rely on strict time synchronization. A discrepancy makes the code invalid before you even enter it.
- The Authenticator app has been reinstalled or the phone has changed, but the account has not been re-registered on the AP-HP side. The old registration then becomes obsolete.
- An update of the app or mobile system has reset the notification settings, preventing the push from being received.
Check your phone’s automatic time and network connection before any other action. If the problem arises from a device change, you need to request an MFA re-registration from IT support. This is not an operation that the user can perform alone.
Browser and cache: invisible errors that persist
The AP-HP webmail portal (Outlook Web App) works better on some browsers than others. An outdated browser or one overloaded with expired cookies can cause redirect loops, blank pages, or certificate errors.
The first instinct to adopt: clear the browser’s cache and cookies, then reload the page. On most browsers, the shortcut Ctrl + Shift + Delete opens the cleanup window directly.
If the error persists, try a private browsing window. This mode ignores the existing cache and extensions. When the connection works in private browsing but not in normal mode, the problem comes from an extension (ad blocker, password manager, built-in VPN) that interferes with the portal.
Disable extensions one by one to identify the one that is blocking. Script blockers are the prime suspects, as the AP-HP portal uses Microsoft scripts for authentication.
Accessing AP-HP messaging from outside: VPN and network
From a location outside the hospital, access to certain AP-HP resources goes through a VPN. The webmail via courriel.aphp.fr is normally accessible without a VPN, but other internal services (intranet, business applications) require it.
The confusion between these two access modes generates errors. If you activate the AP-HP VPN while simply trying to access the webmail, network routing conflicts may arise. The result: the page does not load or displays a timeout error.
For webmail only, disable the VPN and use your regular internet connection. The VPN is only useful for applications that require access to the internal network.
On mobile, another trap exists. If your phone switches between Wi-Fi and mobile data during the connection, the session may be interrupted. The portal interprets the change in IP address as a suspicious connection and logs you out.

Expired password or incorrectly formatted username
AP-HP passwords have a limited lifespan. After this period, the password silently expires. You do not always receive prior notification, especially if you do not regularly check your messaging.
The error message displayed during an attempt with an expired password is often identical to that of an incorrect password. The difference is that retyping the same password will not resolve anything, even if it is technically “correct.” You must go through the reset procedure, accessible from the login page or via support.
The username itself can sometimes pose a problem. The expected format varies: some services require the short login (like firstname.lastname), while others require the full address ([email protected]). Use the exact format indicated on the login page, without adding a domain if only the login is requested.
One last often overlooked point: the Caps Lock key. AP-HP passwords are case-sensitive. An accidental uppercase letter turns every attempt into a failure, and these failures accumulate until lockout. Checking the state of this key before entering your password remains the simplest and most effective action to avoid contacting support.