错误“ AADSTS50076”在使用户访问令牌的同时
我正在尝试使用户访问令牌从node.js代码访问图形API。
My Request:
POST https://login.microsoftonline.com/<AD-Tenant-Id>/oauth2/v2.0/token
client_id: <application ID>
client_secret: <secret string>
scope: User.Read
response_type: "code"
grant_type: "password"
username: <user email>
password: <user password>
I get error:
AADSTS50076: Due to a configuration change made by your administrator,
or because you moved to a new location, you must use multi-factor authentication to access....
我正在使用Postman测试请求。
在我的广告中,我有多因素身份验证。
和“安全默认值”设置为“启用”。
如果我“禁用”“安全默认值”,那么我就能获得令牌。
有没有办法可以在没有用户交互的情况下启用“安全默认值”并获得令牌?
I am trying to get the user access token for accessing Graph APIs from the node.js code.
My Request:
POST https://login.microsoftonline.com/<AD-Tenant-Id>/oauth2/v2.0/token
client_id: <application ID>
client_secret: <secret string>
scope: User.Read
response_type: "code"
grant_type: "password"
username: <user email>
password: <user password>
I get error:
AADSTS50076: Due to a configuration change made by your administrator,
or because you moved to a new location, you must use multi-factor authentication to access....
I am using postman for testing the request.
In my AD I have multi-factor authentication disabled.
And "Security Defaults" are set to "enable".
If I "disable" the "Security Defaults", then I am able to get the token.
Is there a way I can keep the "Security Defaults" enabled and get the token, without the user interaction?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
您可以尝试代表用户获取访问权限,ref doc- https://learn.microsoft.com/en-us/graph/auth-v2-user#3-get-a-token
noreferrer /1.1
主机: https://login.microsoftonline.com
content-type:应用程序/x-www-form-urlencoded
client_id =1111111111-1111-1111-1111-1111111111111111111111111111111111111111111111111111111111
往
&code=OAAABAAAAiL9Kn2Z27UubvWFPbm0gLWQJVzCTE9UkP3pSx1aXxUjq3n8b2JRLk4OxVXr...
&redirect_uri=http%3A%2F%2Flocalhost%2Fmyapp%2F
&grant_type=authorization_code
&amp; client_secret = jxom3iz ...
希望这会有所帮助。
You can try out Get access on behalf of a user , ref doc - https://learn.microsoft.com/en-us/graph/auth-v2-user#3-get-a-token
POST /{tenant}/oauth2/v2.0/token HTTP/1.1
Host: https://login.microsoftonline.com
Content-Type: application/x-www-form-urlencoded
client_id=11111111-1111-1111-1111-111111111111
&scope=user.read%20mail.read
&code=OAAABAAAAiL9Kn2Z27UubvWFPbm0gLWQJVzCTE9UkP3pSx1aXxUjq3n8b2JRLk4OxVXr...
&redirect_uri=http%3A%2F%2Flocalhost%2Fmyapp%2F
&grant_type=authorization_code
&client_secret=jXoM3iz...
Hope this will help.