Skip to content

trying to get Entra ID registration, getting Azure CLI permission error #32670

@bebound

Description

@bebound

Describe the bug

Describe the bug
AADSTS650057: Invalid resource. The client has requested access to a resource which is not listed in the requested permissions in the client's application registration. Client app ID: 04b07795-8ddb-461a-bbee-02f9e1bf7b46(Microsoft Azure CLI). Resource value from request: api://74cc6976-7a58-4bcc-b197-6edc8fb2d4ba. Resource app ID: 74cc6976-7a58-4bcc-b197-6edc8fb2d4ba. List of valid resources from app registration: . Trace ID: 7463f5ce-fc3f-426c-b1e1-310d567b3a01 Correlation ID: fed05e23-dfeb-49b7-ae9b-4872ea919796 Timestamp: 2025-12-26 19:51:49Z

Related command
az login --tenant "[ID]" --scope "[api]"

Errors
AADSTS650057: Invalid resource. The client has requested access to a resource which is not listed in the requested permissions in the client's application registration. Client app ID: 04b07795-8ddb-461a-bbee-02f9e1bf7b46(Microsoft Azure CLI). Resource value from request: api://74cc6976-7a58-4bcc-b197-6edc8fb2d4ba. Resource app ID: 74cc6976-7a58-4bcc-b197-6edc8fb2d4ba. List of valid resources from app registration: . Trace ID: 7463f5ce-fc3f-426c-b1e1-310d567b3a01 Correlation ID: fed05e23-dfeb-49b7-ae9b-4872ea919796 Timestamp: 2025-12-26 19:51:49Z

Issue script & Debug output
?

Expected behavior
get the device enrolled

Environment Summary
azure-cli 2.81.0

core 2.81.0
telemetry 1.1.0

Extensions:
log-analytics 1.0.0b1

Dependencies:
msal 1.34.0b1
azure-mgmt-resource 23.3.0

Python location '/opt/homebrew/Cellar/azure-cli/2.81.0/libexec/bin/python'
Config directory '/Users/mcc0nnell/.azure'
Extensions directory '/Users/mcc0nnell/.azure/cliextensions'

Python (Darwin) 3.13.11 (main, Dec 5 2025, 16:06:33) [Clang 17.0.0 (clang-1700.4.4.1)]

Legal docs and information: aka.ms/AzureCliLegal

Your CLI is up-to-date.

Additional context
No response

Related command

~

Errors

~

Issue script & Debug output

~

Expected behavior

~

Environment Summary

~

Additional context

No response

Metadata

Metadata

Assignees

Labels

Accountaz login/accountAuto-AssignAuto assign by botAuto-ResolveAuto resolve by botAzure CLI TeamThe command of the issue is owned by Azure CLI teamLoginPossible-SolutionSimilar-IssuequestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as that

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions