Azure AD应用清单缓存能否刷新?隐式流获取JWT遇AADSTS70005错误
Answers to Your Azure AD Application Questions
1. Can the Azure AD Application - Manifest settings cache be refreshed?
Absolutely—Azure AD does cache manifest configurations, but there are a few reliable ways to kick off a refresh:
- Force a manifest re-save in the Azure Portal: Head to your app registration, open the manifest editor, make a trivial change (like adding a space to the display name, then reverting it), and hit Save. This triggers Azure AD to reprocess the manifest right away.
- Wait for automatic expiration: The cache usually refreshes on its own within 15 to 60 minutes, so if you can afford to wait, that’s a low-effort option.
- Use Microsoft Graph API to update the app: Sending a small PATCH request (like updating a minor property via
PATCH /applications/{application-id}) will instantly invalidate the cached settings.
2. Fixing the AADSTS70005 Error with Implicit Flow
I’ve run into this exact issue before—even after setting "oauth2AllowImplicitFlow": true in the manifest, the error still pops up. Let’s go through the most common fixes:
- Double-check the manifest save: It sounds obvious, but sometimes the Azure Portal doesn’t persist changes if you navigate away too quickly. Go back to the manifest editor, confirm
"oauth2AllowImplicitFlow": trueis correctly set (notfalse), and click Save again to be sure. - Verify your app’s platform type: Implicit flow only works for Single-Page Applications (SPAs) and public client apps. If your app is registered as a confidential client (like a web app with a client secret), you’ll hit this error regardless of the manifest setting. Check the Authentication blade: under Platform configurations, make sure you’ve added an SPA platform (not just a web platform) if you’re building an SPA.
- Adjust your request’s response_type and scope: Your current request uses
response_type=tokenwithscope=openid—that’s a mismatch. For implicit flow:- If you want an ID token, use
response_type=id_tokenwithscope=openid - If you need an access token, pair
response_type=tokenwith the actual API scopes you need (e.g.,https://graph.microsoft.com/User.Read)
Try updating your request to something like this for an ID token:
Or this for an access token:https://login.microsoftonline.com/{Tenant}/oauth2/v2.0/authorize?client_id={clientid}&redirect_uri={AppRedirectURL}&scope=openid&response_type=id_tokenhttps://login.microsoftonline.com/{Tenant}/oauth2/v2.0/authorize?client_id={clientid}&redirect_uri={AppRedirectURL}&scope=https://graph.microsoft.com/User.Read&response_type=token - If you want an ID token, use
- Clear browser cache and cookies: Old authentication sessions can cause weird caching issues. Try opening an incognito window or clearing your browser’s cache/cookies before testing the request again.
- Ensure redirect URI is an exact match: The redirect URI in your request must perfectly match one of the URIs listed in your app registration’s Authentication blade—even a missing or extra trailing slash can break things.
内容的提问来源于stack exchange,提问作者Dandy
相关产品推荐
相关产品推荐

