|
Connect-MgGraph -Scopes "AppRoleAssignment.ReadWrite.All" -NoWelcome |
Connect-MgGraph on line 193 requests only AppRoleAssignment.ReadWrite.All. New-MgServicePrincipal requires Application.ReadWrite.All. The V1 ATG SP is typically pre-existing so it skips past, but any V2 per-server SP that needs creation hits Authorization_RequestDenied (403).
Fix: add Application.ReadWrite.All to the -Scopes array.
- Connect-MgGraph -Scopes "AppRoleAssignment.ReadWrite.All" -NoWelcome
+ Connect-MgGraph -Scopes "Application.ReadWrite.All","AppRoleAssignment.ReadWrite.All" -NoWelcome
CLI version: 1.1.176, PowerShell 7.5.4, macOS.
Agent365-devTools/scripts/cli/Auth/New-Agent365ToolsServicePrincipalProdPublic.ps1
Line 193 in b76c963
Connect-MgGraphon line 193 requests onlyAppRoleAssignment.ReadWrite.All.New-MgServicePrincipalrequiresApplication.ReadWrite.All. The V1 ATG SP is typically pre-existing so it skips past, but any V2 per-server SP that needs creation hitsAuthorization_RequestDenied (403).Fix: add
Application.ReadWrite.Allto the-Scopesarray.CLI version: 1.1.176, PowerShell 7.5.4, macOS.