You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Microsoft Teams SSO集成:获取令牌时触发2400错误

Angular应用集成Microsoft Teams Azure AD SSO身份验证报错(错误码2400)

当前配置:

  1. 应用托管地址:部署于 https://www.myexampleapp.com/test
  2. Azure AD应用ID URI:api://www.myexampleapp.com/test/12345678-abcd-efgh-ijkl-9876543210
  3. Teams清单:
{
  "$schema": "https://developer.microsoft.com/en-us/json-schemas/teams/v1.16/MicrosoftTeams.schema.json",
  "manifestVersion": "1.16",
  "version": "1.0.2",
  "id": "12345678-abcd-efgh-ijkl-9876543210",
  "packageName": "com.example.teams-tab-app",
  "developer": {
    "name": "Your Name",
    "websiteUrl": "https://example.com",
    "privacyUrl": "https://example.com",
    "termsOfUseUrl": "https://example.com"
  },
  "name": {
    "short": "Teams Tab App",
    "full": "Teams Tab Application"
  },
  "description": {
    "short": "A simple app",
    "full": "This is a simple app built with Angular."
  },
  "staticTabs": [
    {
      "entityId": "exampleTab",
      "name": "Example Tab",
      "contentUrl": "https://www.myexampleapp.com/test",
      "context": ["personalTab", "channelTab"],
      "scopes": ["personal", "team"]
    }
  ],
  "permissions": ["identity", "messageTeamMembers"],
  "validDomains": ["www.myexampleapp.com"],
  "icons": {
    "color": "color.png",
    "outline": "outline.png"
  },
  "accentColor": "#FF5733",
  "webApplicationInfo": {
    "id": "12345678-abcd-efgh-ijkl-9876543210",
    "resource": "api://www.myexampleapp.com/test/12345678-abcd-efgh-ijkl-9876543210"
  }
}
  1. Angular获取令牌代码:
async ngOnInit() {
  microsoftTeams.initialize();
  await this.getAuthToken();
}

async getAuthToken() {
  try {
    this.authToken = await microsoftTeams.authentication.getAuthToken();
    console.log('Authentication token:', this.authToken);
  } catch (error) {
    console.error('Error retrieving token:', error);
  }
}
  1. API权限:
  • User.Read
  • Files.Read.All
  • 其他与网站集和访问审核相关的权限

问题:

调用getAuthToken()获取身份验证令牌时触发错误2400,具体错误信息如下:

ApiContractViolation {"Description":"Embedded browser flow resulted in 'invalid_client' with description '(pii)'","Domain":"com.microsoft.oneauth","ErrorCode":"2400","Message":"The operation attempted is invalid.","SystemErrorCode":"0","Tag":"49dvr","Type":"OneAuth","additional_query_parameters_count":"1","all_error_tags":"49dvr","api_error_code":"0","api_error_context":"Embedded browser flow resulted in 'invalid_client' with description '(pii)'","api_error_tag":"49dvr","api_name":"AcquireTokenInteractively","api_status_code":"StatusInternal::ApiContractViolation","authority_type":"AAD","authorization_type":"Interactive","broker_app_used":"false","browser_navigation_count":"2","client_id":"112345","correlation_id":"12345","is_successful":"false","msal_version":"1.1.0+00747db6","original_authority":"https://login.microsoftonline.com/9229b2d3-b865-4ecb-942b-580b52e63","prt_enabled":"false","read_token":"ART-3d9b2b5ca34b2|FRT-3d9b27eb5ca2","request_duration":"305","request_new_prt":"false","start_time":"2024-08-18T11:32:54.000Z","stop_time":"2024-08-18T11:32:55.000Z","ui_event_count":"1","was_request_throttled":"false"}

错误截图:
错误截图

请求提供排查思路与解决方案。


内容的提问来源于stack exchange,提问作者Talktomegoose

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 10:05:57