You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法通过IMAP OAuth2.0认证Office 365:AUTHENTICATE失败

使用OAuth2.0通过IMAP连接Office 365邮箱时认证失败

我在Node.js应用中通过IMAP协议获取指定邮箱的所有邮件,3天前纯密码认证突然失效,因此改用OAuth2.0认证方式。

我已完成Azure门户的应用注册,并按照微软官方文档指导操作,目前能通过Postman成功获取access_token,以下是Postman生成的Node.js请求代码:

var request = require('request');
var options = {
  'method': 'POST',
  'url': 'https://login.microsoftonline.com/292........f9/oauth2/v2.0/token',
  'headers': {
    'Content-Type': 'application/x-www-form-urlencoded',
    'Cookie': 'fpc=AoRIZjYQr2JOsS57j2DVG4jEeor3AQAAAJtTjtsOAAAA; stsservicecookie=estsfd; x-ms-gateway-slice=estsfd'
  },
  form: {
    'client_id': '124.....1',
    'grant_type': 'client_credentials',
    'response_mode': 'query\n',
    'scope': 'https://outlook.office365.com/.default',
    'client_secret': 'j1....F'
  }
};
request(options, function (error, response) {
  if (error) throw new Error(error);
  console.log(response.body);
});

以下是我用于连接Office 365服务器的IMAP代码:

var Imap = require('node-imap'),  
  inspect = require('util').inspect;  
var buffer = require('buffer').Buffer;
const mailId = 'support@example.com';  
const token = 'ey.......LA';  
const auth2 = buffer.from(`user=${mailId}\x01auth=Bearer ${token}\x01\x01`).toString('base64');  

console.log(`auth2=>`, auth2);

var imap = new Imap({  
  xoauth2: auth2,  
  host: 'outlook.office365.com',  
  port: 993,  
  tls: true,  
  debug: console.log,  
  authTimeout: 25000,  
  connTimeout: 30000,  
  tlsOptions: {  
    rejectUnauthorized: false,  
    servername: 'outlook.office365.com'  
  }  
});  

function openInbox(cb) {  
  imap.openBox('INBOX', true, cb);  
}  

imap.once('ready', function () {  
  openInbox(function (err, box) {  
    if (err) throw err;  
    var f = imap.seq.fetch('1:3', {  
      bodies: 'HEADER.FIELDS (FROM TO SUBJECT DATE)',  
      struct: true  
    });  
    f.on('message', function (msg, seqno) {  
      console.log('Message #%d', seqno);  
      var prefix = '(#' + seqno + ') ';  
      msg.on('body', function (stream, info) {  
        var buffer = '';  
        stream.on('data', function (chunk) {  
          buffer += chunk.toString('utf8');  
        });  
        stream.once('end', function () {  
          console.log(  
            prefix + 'Parsed header: %s',  
            inspect(Imap.parseHeader(buffer))  
          );  
        });  
      });  
      msg.once('attributes', function (attrs) {  
        console.log(prefix + 'Attributes: %s', inspect(attrs, false, 8));  
      });  
      msg.once('end', function () {  
        console.log(prefix + 'Finished');  
      });  
    });  
    f.once('error', function (err) {  
      console.log('Fetch error: ' + err);  
    });  
    f.once('end', function () {  
      console.log('Done fetching all messages!');  
      imap.end();  
    });  
  });  
});  

imap.once('error', function (err) {  
  console.log(err);  
});  

imap.once('end', function () {  
  console.log('Connection ended');  
});  

imap.connect();

运行上述代码后,遇到以下认证失败错误:

Error: AUTHENTICATE failed.
    at Connection
    at TLSSocket.emit (node:events:513:28)
    at emitReadable_ (node:internal/streams/readable:590:12)
    at process.processTicksAndRejections (node:internal/process/task_queues:81:21) {
  type: 'no',
  textCode: undefined,
  source: 'authentication'
}

我已按照文档要求添加了应用权限,权限配置截图如下:
应用注册权限配置

怀疑Azure Active Directory的配置存在遗漏,希望能得到帮助排查问题。

内容的提问来源于stack exchange,提问作者Maninder Singh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 07:27:04