Auth: http://localhost als Redirect-URI (Login auf macOS/Linux)
Auf macOS/Linux nutzt Connect-MgGraph den interaktiven Loopback-Browser-Flow (http://localhost:<zufälliger Port>). Ohne registrierte Loopback-URI scheitert der Login mit AADSTS50011. Setup-AppRegistration.ps1 legt jetzt zusätzlich http://localhost an (portagnostisch); App-Registration.md dokumentiert es. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -85,10 +85,15 @@ sein — sonst scheitert der erste Login (`AADSTS500113` bzw. `AADSTS50011`):
|
|||||||
2. **Redirect-URIs** unter *Mobilgerät- und Desktopanwendungen*:
|
2. **Redirect-URIs** unter *Mobilgerät- und Desktopanwendungen*:
|
||||||
```
|
```
|
||||||
https://login.microsoftonline.com/common/oauth2/nativeclient
|
https://login.microsoftonline.com/common/oauth2/nativeclient
|
||||||
|
http://localhost
|
||||||
ms-appx-web://Microsoft.AAD.BrokerPlugin/<CLIENT-ID>
|
ms-appx-web://Microsoft.AAD.BrokerPlugin/<CLIENT-ID>
|
||||||
```
|
```
|
||||||
- Zeile 1 → **Device-Code-Flow**
|
- Zeile 1 → **Device-Code-Flow**
|
||||||
- Zeile 2 → **WAM-Broker** (Windows-Anmeldefenster); `<CLIENT-ID>` ist die
|
- Zeile 2 → **Loopback / interaktiver Browser-Login** — nötig auf **macOS/Linux**
|
||||||
|
(und überall, wo kein WAM-Broker läuft). Ohne diese URI schlägt der Login mit
|
||||||
|
`AADSTS50011` fehl (`http://localhost:<Port>` passt nicht). `http://localhost`
|
||||||
|
ist portagnostisch, deckt also den zufälligen Port ab.
|
||||||
|
- Zeile 3 → **WAM-Broker** (Windows-Anmeldefenster); `<CLIENT-ID>` ist die
|
||||||
AppId der Registrierung selbst.
|
AppId der Registrierung selbst.
|
||||||
3. **Multi-Tenant:** Wird dieselbe App gegen fremde Tenants genutzt, muss
|
3. **Multi-Tenant:** Wird dieselbe App gegen fremde Tenants genutzt, muss
|
||||||
`signInAudience` auf *Accounts in any organizational directory*
|
`signInAudience` auf *Accounts in any organizational directory*
|
||||||
|
|||||||
@@ -8,7 +8,8 @@
|
|||||||
AADSTS500113 / AADSTS50011 scheitert:
|
AADSTS500113 / AADSTS50011 scheitert:
|
||||||
* Delegierte Microsoft-Graph-Berechtigungen (nach Bedarf: RW, RO, Geraete)
|
* Delegierte Microsoft-Graph-Berechtigungen (nach Bedarf: RW, RO, Geraete)
|
||||||
* "Oeffentliche Clientflows zulassen" (isFallbackPublicClient = true)
|
* "Oeffentliche Clientflows zulassen" (isFallbackPublicClient = true)
|
||||||
* Redirect-URIs fuer Device-Code (nativeclient) und WAM-Broker
|
* Redirect-URIs fuer Device-Code (nativeclient), Loopback/Browser
|
||||||
|
(http://localhost, noetig auf macOS/Linux) und WAM-Broker
|
||||||
* optional Admin-Consent
|
* optional Admin-Consent
|
||||||
|
|
||||||
Nutzt nur Microsoft.Graph.Authentication (Invoke-MgGraphRequest) — dieselbe
|
Nutzt nur Microsoft.Graph.Authentication (Invoke-MgGraphRequest) — dieselbe
|
||||||
@@ -160,6 +161,7 @@ if ($ClientId) {
|
|||||||
requiredResourceAccess = $requiredResourceAccess
|
requiredResourceAccess = $requiredResourceAccess
|
||||||
publicClient = @{ redirectUris = @(
|
publicClient = @{ redirectUris = @(
|
||||||
'https://login.microsoftonline.com/common/oauth2/nativeclient'
|
'https://login.microsoftonline.com/common/oauth2/nativeclient'
|
||||||
|
'http://localhost'
|
||||||
"ms-appx-web://Microsoft.AAD.BrokerPlugin/$appId"
|
"ms-appx-web://Microsoft.AAD.BrokerPlugin/$appId"
|
||||||
) }
|
) }
|
||||||
}
|
}
|
||||||
@@ -184,6 +186,7 @@ if ($ClientId) {
|
|||||||
|
|
||||||
$patch = @{ publicClient = @{ redirectUris = @(
|
$patch = @{ publicClient = @{ redirectUris = @(
|
||||||
'https://login.microsoftonline.com/common/oauth2/nativeclient'
|
'https://login.microsoftonline.com/common/oauth2/nativeclient'
|
||||||
|
'http://localhost'
|
||||||
"ms-appx-web://Microsoft.AAD.BrokerPlugin/$appId"
|
"ms-appx-web://Microsoft.AAD.BrokerPlugin/$appId"
|
||||||
) } }
|
) } }
|
||||||
Invoke-MgGraphRequest -Method PATCH -Uri "https://graph.microsoft.com/v1.0/applications/$objId" `
|
Invoke-MgGraphRequest -Method PATCH -Uri "https://graph.microsoft.com/v1.0/applications/$objId" `
|
||||||
|
|||||||
Reference in New Issue
Block a user