From 51c2f56dec249aa8b844832a232f9f185122d740 Mon Sep 17 00:00:00 2001 From: Marco Wende Date: Wed, 16 Sep 2026 15:56:39 +0200 Subject: [PATCH] Auth: http://localhost als Redirect-URI (Login auf macOS/Linux) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Auf macOS/Linux nutzt Connect-MgGraph den interaktiven Loopback-Browser-Flow (http://localhost:). Ohne registrierte Loopback-URI scheitert der Login mit AADSTS50011. Setup-AppRegistration.ps1 legt jetzt zusätzlich http://localhost an (portagnostisch); App-Registration.md dokumentiert es. Co-Authored-By: Claude Opus 4.8 --- docs/App-Registration.md | 7 ++++++- docs/Setup-AppRegistration.ps1 | 5 ++++- 2 files changed, 10 insertions(+), 2 deletions(-) diff --git a/docs/App-Registration.md b/docs/App-Registration.md index af5ab4f..626badd 100644 --- a/docs/App-Registration.md +++ b/docs/App-Registration.md @@ -85,10 +85,15 @@ sein — sonst scheitert der erste Login (`AADSTS500113` bzw. `AADSTS50011`): 2. **Redirect-URIs** unter *Mobilgerät- und Desktopanwendungen*: ``` https://login.microsoftonline.com/common/oauth2/nativeclient + http://localhost ms-appx-web://Microsoft.AAD.BrokerPlugin/ ``` - Zeile 1 → **Device-Code-Flow** - - Zeile 2 → **WAM-Broker** (Windows-Anmeldefenster); `` ist die + - Zeile 2 → **Loopback / interaktiver Browser-Login** — nötig auf **macOS/Linux** + (und überall, wo kein WAM-Broker läuft). Ohne diese URI schlägt der Login mit + `AADSTS50011` fehl (`http://localhost:` passt nicht). `http://localhost` + ist portagnostisch, deckt also den zufälligen Port ab. + - Zeile 3 → **WAM-Broker** (Windows-Anmeldefenster); `` ist die AppId der Registrierung selbst. 3. **Multi-Tenant:** Wird dieselbe App gegen fremde Tenants genutzt, muss `signInAudience` auf *Accounts in any organizational directory* diff --git a/docs/Setup-AppRegistration.ps1 b/docs/Setup-AppRegistration.ps1 index 5dcd861..e1214e4 100644 --- a/docs/Setup-AppRegistration.ps1 +++ b/docs/Setup-AppRegistration.ps1 @@ -8,7 +8,8 @@ AADSTS500113 / AADSTS50011 scheitert: * Delegierte Microsoft-Graph-Berechtigungen (nach Bedarf: RW, RO, Geraete) * "Oeffentliche Clientflows zulassen" (isFallbackPublicClient = true) - * Redirect-URIs fuer Device-Code (nativeclient) und WAM-Broker + * Redirect-URIs fuer Device-Code (nativeclient), Loopback/Browser + (http://localhost, noetig auf macOS/Linux) und WAM-Broker * optional Admin-Consent Nutzt nur Microsoft.Graph.Authentication (Invoke-MgGraphRequest) — dieselbe @@ -160,6 +161,7 @@ if ($ClientId) { requiredResourceAccess = $requiredResourceAccess publicClient = @{ redirectUris = @( 'https://login.microsoftonline.com/common/oauth2/nativeclient' + 'http://localhost' "ms-appx-web://Microsoft.AAD.BrokerPlugin/$appId" ) } } @@ -184,6 +186,7 @@ if ($ClientId) { $patch = @{ publicClient = @{ redirectUris = @( 'https://login.microsoftonline.com/common/oauth2/nativeclient' + 'http://localhost' "ms-appx-web://Microsoft.AAD.BrokerPlugin/$appId" ) } } Invoke-MgGraphRequest -Method PATCH -Uri "https://graph.microsoft.com/v1.0/applications/$objId" `