如何解决Microsoft Graph API中的AuthenticationError错误?
解决Microsoft Graph API调用/messages或/sendMail时的AADSTS500014错误
错误信息
"code": "AuthenticationError", "message": "AADSTS500014: The service principal for resource 'https://outlook.office365.com/' is disabled. This indicate that a subscription within the tenant has lapsed, or that the administrator for this tenant has disabled the application, preventing tokens from being issued for it. Trace ID: fb68ddac-e1f1-452d-827b-3451f0c0c101 Correlation ID: 1aed6368-ba68-45dc-a5ec-f369f3d3b951 Timestamp: 2024-04-29 10:53:25Z"
排查与解决步骤
- 检查服务主体启用状态:登录Azure门户,进入「Azure Active Directory」→「企业应用程序」,找到你用于Graph API的应用,查看「属性」中的「启用状态」,确保设置为「是」。注意这里的企业应用程序是服务主体实例,和应用注册入口的配置不同。
- 修正资源URI与权限范围:错误信息中提到的资源是
https://outlook.office365.com/,但调用Microsoft Graph API时,正确的资源URI应为https://graph.microsoft.com/。获取accessToken时,需指定Graph相关的权限范围,比如Mail.Read、Mail.Send,而非Outlook相关的旧范围。 - 确认租户订阅有效性:联系租户管理员,确认租户的Microsoft 365/Exchange Online订阅处于活跃状态,未过期或被禁用。
- 验证应用权限配置:进入「应用注册」→ 目标应用 →「API权限」,确保已添加Microsoft Graph的权限(委派或应用权限),且需管理员同意的权限已完成授权。
注意事项
Thunderbird使用POP/IMAP/SMTP协议,其认证机制与Microsoft Graph API的OAuth2授权流程完全独立,因此Thunderbird能正常收发邮件无法直接证明Graph API的配置无误。
内容的提问来源于stack exchange,提问作者Sergi Romero
相关产品推荐
相关产品推荐

