The following forum(s) have migrated to Microsoft Q&A (Preview): Azure Active Directory!
Visit Microsoft Q&A (Preview) to post new questions.

Learn More

Protect an API by using OAuth 2.0 with Azure Active Directory and API Management RRS feed

All replies

  • Have you given proper permissions in App registration page to the web api you are calling through the registered client app. Refer to Grant permissions in Azure AD section of the document.

    Also, can you provide the full error message over here.

    Tuesday, September 10, 2019 10:54 PM
  • Yes i do that 
    HTTP/1.1 401 Unauthorized
    date: Wed, 11 Sep 2019 08:15:51 GMT
    vary: Origin
    content-type: application/json
    content-length: 85
        "statusCode": 401,
        "message": "Unauthorized. Access token is missing or invalid."
    Wednesday, September 11, 2019 8:51 AM
  • Have you added OAuth2 authorization server to your API management instance.  Please refer to How to authorize developer accounts using OAuth 2.0 in Azure API Management

    And then you need to configure the API to use OAuth2 authorization from the Publisher portal (Security tab of the API properties) or from the Azure portal (under security). 

    Monday, September 16, 2019 11:37 PM