使用OAuth 2.0资源所有者密码凭证调用Microsoft身份平台遇AADSTS50126错误
问题:调用Microsoft Identity Platform时返回AADSTS50126错误
我使用以下curl请求访问Microsoft Identity Platform:
curl --location 'https://login.microsoftonline.com/tentId/oauth2/v2.0/token' \ --header 'Content-Type: application/x-www-form-urlencoded' \ --data-urlencode 'client_id=xxxxxxxxx' \ --data-urlencode 'scope=User.Read profile openid email' \ --data-urlencode 'grant_type=password' \ --data-urlencode 'username=ravindra1437_outlook.com#EXT#@ravinavyamullamurioutlook.onmicrosoft.com'\ --data-urlencode 'password=xxxxxxxxxxxx' \ --data-urlencode 'client_secret=xxxxxxxxxx'
已确认用户名和密码正确,但仍收到错误:
{"error": "invalid_grant","error_description": "AADSTS50126: Error validating credentials due to invalid username or password.\r\nTrace ID: bb4dd885-c0a7-4985-8d95-45c520710800\r\nCorrelation ID: 7eb0748c-6450-462d-8cd5-c48cd869d59c\r\nTimestamp: 2023-04-20 04:07:49Z","error_codes": [50126],"timestamp": "2023-04-20 04:07:49Z","trace_id": "bb4dd885-c0a7-4985-8d95-45c520710800","correlation_id": "7eb0748c-6450-462d-8cd5-c48cd869d59c","error_uri": "https://login.microsoftonline.com/error?code=50126"}
排查与解决建议
- 修正租户ID拼写:请求URL中的
tentId是拼写错误,需改为tenantId,并替换为你的实际租户ID(GUID或租户域名)。路由错误会直接导致凭证验证失败。 - 检查用户名格式:外部用户的
#EXT#标识需确保格式正确,尝试用原生邮箱ravindra1437@outlook.com替代带租户后缀的用户名测试,确认是否是用户名格式问题。 - 排除MFA限制:密码授权流(grant_type=password)不支持多重身份验证(MFA),若用户开启了MFA,该流会直接报错。此时需切换到授权码流等支持MFA的认证方式。
- 验证应用配置:确保Azure AD中你的应用已启用密码授权流,且所需的API权限(如User.Read)已配置并获得管理员同意(若需管理员授权)。
- 确认用户状态:检查该用户在租户中是否处于活跃状态,未被禁用或删除,且允许使用密码登录。
- 核对密码编码:若密码包含特殊字符,确认
--data-urlencode是否正确处理了特殊字符,可尝试更换一个不含特殊字符的测试密码验证。
内容的提问来源于stack exchange,提问作者Ravindra Babu
相关产品推荐
相关产品推荐

