diff --git a/docs/App-Registration.md b/docs/App-Registration.md index af5ab4f..626badd 100644 --- a/docs/App-Registration.md +++ b/docs/App-Registration.md @@ -85,10 +85,15 @@ sein — sonst scheitert der erste Login (`AADSTS500113` bzw. `AADSTS50011`): 2. **Redirect-URIs** unter *Mobilgerät- und Desktopanwendungen*: ``` https://login.microsoftonline.com/common/oauth2/nativeclient + http://localhost ms-appx-web://Microsoft.AAD.BrokerPlugin/ ``` - Zeile 1 → **Device-Code-Flow** - - Zeile 2 → **WAM-Broker** (Windows-Anmeldefenster); `` ist die + - Zeile 2 → **Loopback / interaktiver Browser-Login** — nötig auf **macOS/Linux** + (und überall, wo kein WAM-Broker läuft). Ohne diese URI schlägt der Login mit + `AADSTS50011` fehl (`http://localhost:` passt nicht). `http://localhost` + ist portagnostisch, deckt also den zufälligen Port ab. + - Zeile 3 → **WAM-Broker** (Windows-Anmeldefenster); `` ist die AppId der Registrierung selbst. 3. **Multi-Tenant:** Wird dieselbe App gegen fremde Tenants genutzt, muss `signInAudience` auf *Accounts in any organizational directory* diff --git a/docs/Setup-AppRegistration.ps1 b/docs/Setup-AppRegistration.ps1 index 5dcd861..e1214e4 100644 --- a/docs/Setup-AppRegistration.ps1 +++ b/docs/Setup-AppRegistration.ps1 @@ -8,7 +8,8 @@ AADSTS500113 / AADSTS50011 scheitert: * Delegierte Microsoft-Graph-Berechtigungen (nach Bedarf: RW, RO, Geraete) * "Oeffentliche Clientflows zulassen" (isFallbackPublicClient = true) - * Redirect-URIs fuer Device-Code (nativeclient) und WAM-Broker + * Redirect-URIs fuer Device-Code (nativeclient), Loopback/Browser + (http://localhost, noetig auf macOS/Linux) und WAM-Broker * optional Admin-Consent Nutzt nur Microsoft.Graph.Authentication (Invoke-MgGraphRequest) — dieselbe @@ -160,6 +161,7 @@ if ($ClientId) { requiredResourceAccess = $requiredResourceAccess publicClient = @{ redirectUris = @( 'https://login.microsoftonline.com/common/oauth2/nativeclient' + 'http://localhost' "ms-appx-web://Microsoft.AAD.BrokerPlugin/$appId" ) } } @@ -184,6 +186,7 @@ if ($ClientId) { $patch = @{ publicClient = @{ redirectUris = @( 'https://login.microsoftonline.com/common/oauth2/nativeclient' + 'http://localhost' "ms-appx-web://Microsoft.AAD.BrokerPlugin/$appId" ) } } Invoke-MgGraphRequest -Method PATCH -Uri "https://graph.microsoft.com/v1.0/applications/$objId" `