Auth: http://localhost als Redirect-URI (Login auf macOS/Linux)

Auf macOS/Linux nutzt Connect-MgGraph den interaktiven Loopback-Browser-Flow
(http://localhost:<zufälliger Port>). Ohne registrierte Loopback-URI scheitert
der Login mit AADSTS50011. Setup-AppRegistration.ps1 legt jetzt zusätzlich
http://localhost an (portagnostisch); App-Registration.md dokumentiert es.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-09-16 15:56:39 +02:00
co-authored by Claude Opus 4.8
parent e652891c41
commit 51c2f56dec
2 changed files with 10 additions and 2 deletions
+6 -1
View File
@@ -85,10 +85,15 @@ sein — sonst scheitert der erste Login (`AADSTS500113` bzw. `AADSTS50011`):
2. **Redirect-URIs** unter *Mobilgerät- und Desktopanwendungen*:
```
https://login.microsoftonline.com/common/oauth2/nativeclient
http://localhost
ms-appx-web://Microsoft.AAD.BrokerPlugin/<CLIENT-ID>
```
- Zeile 1 → **Device-Code-Flow**
- Zeile 2 → **WAM-Broker** (Windows-Anmeldefenster); `<CLIENT-ID>` ist die
- Zeile 2 → **Loopback / interaktiver Browser-Login** — nötig auf **macOS/Linux**
(und überall, wo kein WAM-Broker läuft). Ohne diese URI schlägt der Login mit
`AADSTS50011` fehl (`http://localhost:<Port>` passt nicht). `http://localhost`
ist portagnostisch, deckt also den zufälligen Port ab.
- Zeile 3 → **WAM-Broker** (Windows-Anmeldefenster); `<CLIENT-ID>` ist die
AppId der Registrierung selbst.
3. **Multi-Tenant:** Wird dieselbe App gegen fremde Tenants genutzt, muss
`signInAudience` auf *Accounts in any organizational directory*
+4 -1
View File
@@ -8,7 +8,8 @@
AADSTS500113 / AADSTS50011 scheitert:
* Delegierte Microsoft-Graph-Berechtigungen (nach Bedarf: RW, RO, Geraete)
* "Oeffentliche Clientflows zulassen" (isFallbackPublicClient = true)
* Redirect-URIs fuer Device-Code (nativeclient) und WAM-Broker
* Redirect-URIs fuer Device-Code (nativeclient), Loopback/Browser
(http://localhost, noetig auf macOS/Linux) und WAM-Broker
* optional Admin-Consent
Nutzt nur Microsoft.Graph.Authentication (Invoke-MgGraphRequest) — dieselbe
@@ -160,6 +161,7 @@ if ($ClientId) {
requiredResourceAccess = $requiredResourceAccess
publicClient = @{ redirectUris = @(
'https://login.microsoftonline.com/common/oauth2/nativeclient'
'http://localhost'
"ms-appx-web://Microsoft.AAD.BrokerPlugin/$appId"
) }
}
@@ -184,6 +186,7 @@ if ($ClientId) {
$patch = @{ publicClient = @{ redirectUris = @(
'https://login.microsoftonline.com/common/oauth2/nativeclient'
'http://localhost'
"ms-appx-web://Microsoft.AAD.BrokerPlugin/$appId"
) } }
Invoke-MgGraphRequest -Method PATCH -Uri "https://graph.microsoft.com/v1.0/applications/$objId" `