Auth: http://localhost als Redirect-URI (Login auf macOS/Linux)
Auf macOS/Linux nutzt Connect-MgGraph den interaktiven Loopback-Browser-Flow (http://localhost:<zufälliger Port>). Ohne registrierte Loopback-URI scheitert der Login mit AADSTS50011. Setup-AppRegistration.ps1 legt jetzt zusätzlich http://localhost an (portagnostisch); App-Registration.md dokumentiert es. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -8,7 +8,8 @@
|
||||
AADSTS500113 / AADSTS50011 scheitert:
|
||||
* Delegierte Microsoft-Graph-Berechtigungen (nach Bedarf: RW, RO, Geraete)
|
||||
* "Oeffentliche Clientflows zulassen" (isFallbackPublicClient = true)
|
||||
* Redirect-URIs fuer Device-Code (nativeclient) und WAM-Broker
|
||||
* Redirect-URIs fuer Device-Code (nativeclient), Loopback/Browser
|
||||
(http://localhost, noetig auf macOS/Linux) und WAM-Broker
|
||||
* optional Admin-Consent
|
||||
|
||||
Nutzt nur Microsoft.Graph.Authentication (Invoke-MgGraphRequest) — dieselbe
|
||||
@@ -160,6 +161,7 @@ if ($ClientId) {
|
||||
requiredResourceAccess = $requiredResourceAccess
|
||||
publicClient = @{ redirectUris = @(
|
||||
'https://login.microsoftonline.com/common/oauth2/nativeclient'
|
||||
'http://localhost'
|
||||
"ms-appx-web://Microsoft.AAD.BrokerPlugin/$appId"
|
||||
) }
|
||||
}
|
||||
@@ -184,6 +186,7 @@ if ($ClientId) {
|
||||
|
||||
$patch = @{ publicClient = @{ redirectUris = @(
|
||||
'https://login.microsoftonline.com/common/oauth2/nativeclient'
|
||||
'http://localhost'
|
||||
"ms-appx-web://Microsoft.AAD.BrokerPlugin/$appId"
|
||||
) } }
|
||||
Invoke-MgGraphRequest -Method PATCH -Uri "https://graph.microsoft.com/v1.0/applications/$objId" `
|
||||
|
||||
Reference in New Issue
Block a user