Script Troubleshooting
The table below summarizes the possible errors regarding Token connection issues.
|
Symptom |
Likely Cause |
|---|---|
|
Token request fails with AADSTS500011 (resource not found) |
The server app service principal was not created in your tenant (setup step 1). |
|
The token has no roles claim, or the API returns 401/403 |
The app role permission was not added, or admin consent was not granted (setup step 2). |
|
The token has no roles claim, or the API returns 401/403 |
The app role permission was not added, or admin consent was not granted (setup step 2). |
|
API returns 401 with a valid token |
ValidIssuers does not contain https://sts.windows.net/<Your AAD Tenant ID>/ , or one of the AzureAdJwt.* values is wrong. |
|
invalid_client on token request |
The client secret is wrong or has expired. Create a new secret. |
|
API returns 401 after about an hour |
The token has expired. Request a new one. |
| ■ | Script Security permissions: The following error below may be displayed if there are security permission issues running the script: |
| ➢ | Do the following: |
| 1. | On the Windows server PC where you are running the script, ensure that you have installed all relevant Windows Security updates. |
| 2. | Open the Windows Local Group Policy Editor. |
| 3. | Navigate to Local Computer Policy > Computer Configuration > Administrative Templates > Windows Components > Windows PowerShell. |
| 4. | Select the Enabled check box to Turn on Script Execution policy. |
| 5. | From the Execution Policy drop-down list, select Allow local scripts and remote signed scripts. See also Script Execution Issues. |