You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD应用清单缓存能否刷新?隐式流获取JWT遇AADSTS70005错误

Answers to Your Azure AD Application Questions

1. Can the Azure AD Application - Manifest settings cache be refreshed?

Absolutely—Azure AD does cache manifest configurations, but there are a few reliable ways to kick off a refresh:

  • Force a manifest re-save in the Azure Portal: Head to your app registration, open the manifest editor, make a trivial change (like adding a space to the display name, then reverting it), and hit Save. This triggers Azure AD to reprocess the manifest right away.
  • Wait for automatic expiration: The cache usually refreshes on its own within 15 to 60 minutes, so if you can afford to wait, that’s a low-effort option.
  • Use Microsoft Graph API to update the app: Sending a small PATCH request (like updating a minor property via PATCH /applications/{application-id}) will instantly invalidate the cached settings.

2. Fixing the AADSTS70005 Error with Implicit Flow

I’ve run into this exact issue before—even after setting "oauth2AllowImplicitFlow": true in the manifest, the error still pops up. Let’s go through the most common fixes:

  • Double-check the manifest save: It sounds obvious, but sometimes the Azure Portal doesn’t persist changes if you navigate away too quickly. Go back to the manifest editor, confirm "oauth2AllowImplicitFlow": true is correctly set (not false), and click Save again to be sure.
  • Verify your app’s platform type: Implicit flow only works for Single-Page Applications (SPAs) and public client apps. If your app is registered as a confidential client (like a web app with a client secret), you’ll hit this error regardless of the manifest setting. Check the Authentication blade: under Platform configurations, make sure you’ve added an SPA platform (not just a web platform) if you’re building an SPA.
  • Adjust your request’s response_type and scope: Your current request uses response_type=token with scope=openid—that’s a mismatch. For implicit flow:
    • If you want an ID token, use response_type=id_token with scope=openid
    • If you need an access token, pair response_type=token with the actual API scopes you need (e.g., https://graph.microsoft.com/User.Read)
      Try updating your request to something like this for an ID token:
    https://login.microsoftonline.com/{Tenant}/oauth2/v2.0/authorize?client_id={clientid}&redirect_uri={AppRedirectURL}&scope=openid&response_type=id_token
    
    Or this for an access token:
    https://login.microsoftonline.com/{Tenant}/oauth2/v2.0/authorize?client_id={clientid}&redirect_uri={AppRedirectURL}&scope=https://graph.microsoft.com/User.Read&response_type=token
    
  • Clear browser cache and cookies: Old authentication sessions can cause weird caching issues. Try opening an incognito window or clearing your browser’s cache/cookies before testing the request again.
  • Ensure redirect URI is an exact match: The redirect URI in your request must perfectly match one of the URIs listed in your app registration’s Authentication blade—even a missing or extra trailing slash can break things.

内容的提问来源于stack exchange,提问作者Dandy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 08:27:05