<h2>[Microsoft SharePoint spoke] - 401 - Invalid username/password combo - Azure Permissions Required</h2><br/><div style="overflow-x:auto"><article><div ><h3 >Issue </h3><section><style type="text/css"><!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } </style> <div class="ns-kb-css-body-editor-container"> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><span style="font-size: 10pt;">Consider the scenario where the <strong>Microsoft SharePoint spoke</strong> is installed and the App is registered in the Azure AD(Active Directory) Portal</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Testing one of the <strong>Actions</strong> (i.e. <em>Get Site</em>) returns the following error message:</span></li></ul> <p style="padding-left: 40px;"><span style="font-size: 10pt;"><code>Error message: Method failed: (/_api/web/XXXXXXX) with code: <em>401 - Invalid username/password combo</em></code></span></p> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><span style="font-size: 10pt;">And the <em>Response Body</em>:</span></li></ul> <p style="padding-left: 40px;"><span style="font-size: 10pt;"><code>Response Body: {"error_description":"ID3035: The request was not valid or is malformed."}</code></span></p> <span id="ns-kb-css-end-div-identifier" style="display: none; pointer-events: none;"></span></div></section></div><div ><h3 >Release</h3><section><style type="text/css"><!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } </style> <div class="ns-kb-css-body-editor-container"> <ul style="list-style-position: inside;"><li><span style="font-size: 10pt;">Observed in <strong>Rome</strong></span></li></ul> <span id="ns-kb-css-end-div-identifier" style="display: none; pointer-events: none;"></span></div></section></div><div ><h3 >Cause</h3><section><style type="text/css"><!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } </style> <div class="ns-kb-css-body-editor-container"> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><span style="font-size: 10pt;">This happens when the set of<strong> Permissions </strong>assigned in the<strong> Azure Apps</strong> <strong>doesn't provide enough privileges</strong> to run the required <em>Action</em>(s).</span></li></ul> <span id="ns-kb-css-end-div-identifier" style="display: none; pointer-events: none;"></span></div></section></div><div ><h3 >Resolution</h3><section><style type="text/css"><!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } </style> <div class="ns-kb-css-body-editor-container"> <ul style="list-style-position: inside;"><li><span style="font-size: 10pt;">Currently, almost all of the <strong>Microsoft SharePoint spoke <em>Actions </em></strong>use two <a title="connection and credentials" href="https://docs.servicenow.com/en-US/bundle/sandiego-application-development/page/administer/integrationhub-store-spokes/concept/sharepoint-online-spoke.html#d2260775e282" target="_blank" rel="noopener noreferrer">connection and credential</a> alias records: </span><span style="color: #008080; font-size: 10pt;"><strong>Sharepoint Online, and </strong></span><span style="color: #008080; font-size: 10pt;"><strong>SharePoint Graph </strong><span style="color: #000000;">(o</span><span style="color: #000000;"><span style="font-size: 10pt;">nly the <em>Create Root Site Subscription </em>uses the </span></span></span><span style="font-size: 10pt;"><span style="color: #000000;"><strong><span style="color: #008080;">SharePoint Graph Root Site Subscription</span></strong><span style="color: #000000;">).</span></span></span></li><li><span style="font-size: 10pt;"><span style="color: #000000;"><span style="color: #000000;">To resolve the issue the below requirements must be fulfilled to prevent/resolve the mentioned error message.</span></span></span></li></ul> <ul><li style="list-style-type: none;"> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Sharepoint Online</strong></span><br /> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><span style="font-size: 10pt;">Its related OAuth Provider record defined in the instance uses <em><strong>Client Credentials <span style="color: #ff0000;">(*)</span></strong></em> as the default grant type. </span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">The corresponding Azure App permission should be set as follows:</span><br /> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><span style="font-size: 10pt;">Under API Permissions, add the SharePoint permission:</span><br /> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><span style="font-size: 10pt;">Click Add permission.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Select <strong><em>SharePoint</em></strong>.</span></li><li style="font-size: 10pt;"><span style="color: #000000; font-size: 10pt;">Select <strong><em>Application <span style="color: #ff0000;">(*)</span></em></strong> Permissions.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">From the Sites list, select the <em>Sites.FullControl.All</em> permission.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Click Add permissions.</span></li></ul> </li><li style="font-size: 10pt;"><span style="font-size: 10pt;"><em>Grant Admin consent</em> for <em>ServiceNowAppName </em>(the <em>Admin Consent Required</em> column is set to <em>Yes</em>).</span></li></ul> </li><li><span style="font-size: 10pt;"><em><strong><span style="color: #ff0000;">(*)</span></strong></em><span style="color: #000000;"><span style="color: #008080;"> Application Type</span> permissions are generally used by services that should not have any user interaction. This Permission Type works in combination with the <span style="color: #008080;">Client Credentials</span> Grant Type (non-interactive).</span></span></li></ul> </li></ul> </li></ul> <ul><li style="list-style-type: none;"> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>SharePoint Graph</strong></span><br /> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><span style="font-size: 10pt;">Its related OAuth Provider record defined in the instance uses <em><strong>Authorization Code</strong> <strong><span style="color: #ff0000;">(**) </span></strong></em>as the default grant type.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">The corresponding Azure App permission should be set as follows:</span><br /> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><span style="font-size: 10pt;">Under API Permissions, add the Microsoft Graph permission:</span><br /> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><span style="font-size: 10pt;">Click Add permission.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Select <em><strong>Microsoft Graph</strong></em>.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Select <em><strong>Delegated</strong> <span style="color: #ff0000;"><strong>(**)</strong></span></em> Permissions.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">From the Sites list, select <em>Sites.ReadWrite.All </em>permission.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">From the User list, select <em>User.Read</em> permission.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Click Add permissions.</span></li></ul> </li><li><span style="font-size: 10pt;"><em>Grant Admin consent</em> for <em>ServiceNowAppName </em>should be set for the SharePoint Graph, alternatively, an assigned account that is Admin in Azure should be dedicated to retrieving the <span style="color: #000000;"><em><span style="text-decoration: underline;">Refresh Token</span></em></span><span style="color: #000000;"> (and its <span style="text-decoration: underline;"><em>Access Token</em></span>) </span>from the instance. Once the <span style="color: #000000;"><em><span style="text-decoration: underline;">Refresh Token</span></em></span> is retrieved it can be used by any user in the instance to get a new valid <span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;"><em>Access Token</em></span></span>.</span></li></ul> </li><li><span style="font-size: 10pt;"><em><span style="color: #ff0000;"><strong>(**)</strong></span></em><span style="color: #000000;"><span style="color: #008080;"> Delegated Type</span> permissions require a signed-in user. This Permission Type works in combination with the <span style="color: #008080;">Authorization Code</span> (or any other login flow). When a new <em><span style="text-decoration: underline;">Refresh Token/Access Token</span></em> retrieval is initiated (i.e. Get OAuth Token UI Action) the instance will prompt for consent and a valid user account should log in to approve. If Admin consent was granted, any authorized Azure user account is able to retrieve a valid <em><span style="text-decoration: underline;">Refresh Token/Access Token</span></em>, <em>alternatively</em> the dedicated Azure Admin account is required or the retrieved <em><span style="text-decoration: underline;">Refresh Token/Access Token</span></em> will not have enough privileges to run the Actions.</span></span></li></ul> </li></ul> </li></ul> <span id="ns-kb-css-end-div-identifier" style="display: none; pointer-events: none;"></span></div></section></div><div ><h3 >Related Links</h3><section><style type="text/css"><!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } </style> <div class="ns-kb-css-body-editor-container"> <ul style="list-style-position: inside;"><li><strong><span style="font-size: 10pt;">ServiceNow Docs</span></strong><br /> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><span style="font-size: 10pt;"><a title="Configure the SharePoint Graph connection and credential alias record" href="https://docs.servicenow.com/bundle/sandiego-application-development/page/administer/integrationhub-store-spokes/task/conf-sharept-graph.html" target="_blank" rel="noopener noreferrer">Configure the SharePoint Graph connection and credential alias record</a> </span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;"><a title="Configure the SharePoint Online connection and credential alias record" href="https://docs.servicenow.com/bundle/sandiego-application-development/page/administer/integrationhub-store-spokes/task/configure-ms-sharepoint.html" target="_blank" rel="noopener noreferrer">Configure the SharePoint Online connection and credential alias record</a></span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;"><a title="Configure the SharePoint Graph Root Site Subscription connection and credential alias record" href="https://docs.servicenow.com/bundle/sandiego-application-development/page/administer/integrationhub-store-spokes/task/conf-graph-root.html" target="_blank" rel="noopener noreferrer">Configure the SharePoint Graph Root Site Subscription connection and credential alias record</a></span></li></ul> </li></ul> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><strong><span style="font-size: 10pt;">Microsoft Docs</span></strong><br /> <ul style="list-style-position: inside;"><li style="font-size: 10pt;"><span style="font-size: 10pt;"><a title="Microsoft Graph permissions" href="https://docs.microsoft.com/en-us/graph/auth/auth-concepts#microsoft-graph-permissions" target="_blank" rel="noopener noreferrer">Microsoft Graph permissions</a></span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;"><a title="Granting access via Azure AD App-Only (see where API permissions are mentioned)" href="https://docs.microsoft.com/en-us/sharepoint/dev/solution-guidance/security-apponly-azuread#setting-up-an-azure-ad-app-for-app-only-access" target="_blank" rel="noopener noreferrer">Granting access via Azure AD App-Only (see where API permissions are mentioned)</a></span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;"><a title="Consent and permissions overview" href="https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/consent-and-permissions-overview" target="_blank" rel="noopener noreferrer">Consent and permissions overview</a></span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;"><a title="Microsoft identity platform and OAuth 2.0 authorization code flow" href="https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-oauth2-on-behalf-of-flow" target="_blank" rel="noopener noreferrer">Microsoft identity platform and OAuth 2.0 authorization code flow</a></span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;"><a title="Microsoft identity platform and the OAuth 2.0 client credentials flow" href="https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-oauth2-client-creds-grant-flow" target="_blank" rel="noopener noreferrer">Microsoft identity platform and the OAuth 2.0 client credentials flow</a></span></li></ul> </li></ul> <span id="ns-kb-css-end-div-identifier" style="display: none; pointer-events: none;"></span></div></section></div></article></div>