Published app fails to retrieve SharePoint data — AADSTS50158 (Conditional Access step-up not completed)
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 45/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- azure, typescript
- 领域
- authentication, backend, cloud
调研方向
The issue is in the published app's token acquisition path within the Microsoft Managed Apps runtime. Start by examining the authentication flow in the runtime code, likely in packages handling the shared_sharepointonline connector or APIM calls. Compare how tokens are obtained in local dev (ms app dev) versus the published runtime on play.managedapps.cloud.microsoft. Look for handling of the interaction_required error and the claims parameter challenge. Testing requires a tenant with Conditional Access policies to reproduce the step-up failure.
由索引模型根据 Issue 内容生成。
描述
Summary
A Microsoft Managed App that reads a SharePoint Online list works correctly in local development (ms app dev), but the same data-source call fails once the app is published/deployed and accessed via play.managedapps.cloud.microsoft. The APIM/APIHub call to the SharePoint connector returns interaction_required (AADSTS50158), indicating a Conditional Access claims challenge that was never satisfied for the token used by the published runtime.
Environment
- Product: Microsoft Managed Apps (
@microsoft/managed-apps-cli, "Cowork" app runtime) - Host:
https://play.managedapps.cloud.microsoft/ - Data source: SharePoint Online (Shared connector
shared_sharepointonline), table binding to a SharePoint list ("AI Use Cases") - Local dev: works —
ms app dev, same tenant, same user, same data source binding - Published app: fails consistently with the error below
- Tenant: isolutionsch.sharepoint.com tenant (Entra tenant id
a6bbab92-053e-490b-bd7e-5cd03763b746)
Repro steps
- Create an app with
ms app create, add a SharePoint Online table data source (ms app add data-source --api-id shared_sharepointonline --as table), bind to list "AI Use Cases". - Verify data loads correctly with
ms app dev(local dev works fine). - Deploy the app with
ms app deploy. - Open the published app via
ms app play/play.managedapps.cloud.microsoft. - Observe the page that fetches list items fails to load data.
Expected behavior
The published app successfully retrieves SharePoint list items, same as in local dev.
Actual behavior
The browser network trace shows the following failing request:
GET https://8d74cbe1-1694-e06b-9bf4-7288dbff2d46.10.common.europe002.azure-apihub.net/apim/sharepointonline/shared-sharepointonl-40490a90-2c30-4d19-a9a1-747639ff0a39/datasets/https%3A%2F%2Fisolutionsch.sharepoint.com%2Fsites%2F006753/tables/AI%20Use%20Cases/items
Referer: https://play.managedapps.cloud.microsoft/
Headers of note: x-ms-client-app-id: 23c4a1e5-8e09-453b-a0ac-7751f8c28cdb
x-ms-protocol-semantics: cdp
Authorization: Bearer <redacted JWT — aud=https://apihub.azure.com, appid=3e62f81e-590b-425b-9531-cad6683656cf, scp=Runtime.All>
Response body:
{
"error": "interaction_required",
"error_description": "AADSTS50158: External security challenge not satisfied. User will be redirected to another page or authentication provider to satisfy additional authentication challenges.",
"error_codes": [50158],
"suberror": "basic_action",
"claims": "{\"access_token\":{\"capolids\":{\"essential\":true,\"values\":[\"88a19af6-da15-4acc-815a-0749adcbde19\",\"7bcdfcc7-8039-4fa0-9e78-c349b103de2b\",\"33f59b3d-d9cf-4023-8b55-8a29a1664495\"]}}}",
"trace_id": "ba8756e7-4441-4c07-8d74-1233e9d06000",
"correlation_id": "e60f356a-e692-44af-ab13-1e8e048d9e2f",
"timestamp": "2026-09-23 08:02:31Z"
}
Hypothesis / suspected root cause
Local dev (ms app dev) obtains its access token through a full interactive browser sign-in, which is able to satisfy Conditional Access step-up requirements (the capolids in the claims challenge). The published app runtime, embedded in the play.managedapps.cloud.microsoft host, appears to acquire/reuse a token silently and does not resubmit the token request with the returned claims parameter to trigger the required step-up authentication (e.g., an interactive prompt/redirect for the additional CA challenge). As a result, every data call from the published app fails with interaction_required, even though the exact same user/tenant/data source works fine in local dev.
This looks like it needs a fix in the published-app auth/token-acquisition path (either surfacing an interactive re-auth prompt within the host iframe, or forwarding the claims challenge on retry) rather than being an app-configuration issue — the CA policy and user are the same across both dev and published, only the runtime differs.
Impact
Any published Managed App whose data source is protected by a Conditional Access policy requiring step-up authentication (device compliance, MFA, etc.) is unable to retrieve data at all — this appears to fully block the connector for affected tenants/users, though it works fine in local dev, so it may not be caught during development.
Additional notes
- Full name/UPN and the bearer JWT have been redacted from this report before sharing externally.
- Happy to provide the full HAR/network trace or additional repro details on request via a private channel.
- 主要语言
- TypeScript
- 星标
- 11
- 派生
- 7
- 平均合并
- 3 天 9 小时
- 30 天内合并 PR
- 5
环境准备
我们还没有检查这个项目的环境配置文件。先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
microsoft/managed-apps 的其他 Issue
-
难度 4/5 3-5 天 新手友好度 52/100
microsoft/managed-apps#34 ·
-
难度 4/5 3-5 天 新手友好度 52/100
microsoft/managed-apps#29 · 1 条评论 ·
查看 microsoft/managed-apps 的全部 Issue
相似的 Issue
-
area/frontend good first issue kind/cooldown
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 85/100
voidzero-dev/oxc-angular-compiler#511 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 78/100
langchain-ai/deepagentsjs#898 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 92/100
anomalyco/models.dev#8509 · 2 条评论 ·
维护者通常 1 天内回复
-
bug documentation P2 UI/UX
难度 2/5 1-3 小时 新手友好度 85/100
维护者通常 1 天内回复