400 Bad Request UndefinedScope ProfileBadRequestException on /oidc/userinfo for some users

%3CLINGO-SUB%20id%3D%22lingo-sub-2403489%22%20slang%3D%22en-US%22%3E400%20Bad%20Request%20UndefinedScope%20ProfileBadRequestException%20on%20%2Foidc%2Fuserinfo%20for%20some%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2403489%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3Eour%20working%20setup%20stopped%20working%20sometime%20at%20the%20end%20of%20may%20(not%20sure%20of%20the%20exact%20date).%20We%20request%20a%20token%20from%20the%20authorization%20endpoint%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Flogin.microsoftonline.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Flogin.microsoftonline.com%2F%3C%2FA%3E%3CTENANT-ID%3E%2Foauth2%2Fv2.0%2Fauthorize%20with%20the%20following%20scopes%3A%20%22openid%20User.read%20profile%22%3C%2FTENANT-ID%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewe%20then%20issue%20a%20request%20to%20%3CSPAN%20class%3D%22tabpanel-summary-value%20textbox-input%20devtools-monospace%22%3E%3CA%20href%3D%22https%3A%2F%2Fgraph.microsoft.com%2Foidc%2Fuserinfo%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgraph.microsoft.com%2Foidc%2Fuserinfo%3C%2FA%3E%20with%20the%20Authorization%3A%20Bearer%20%3CTOKEN%3E%20and%20get%3CBR%20%2F%3E%3C%2FTOKEN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-json%22%3E%3CCODE%3E%7B%0A%20%20%22error%22%3A%20%7B%0A%20%20%20%20%22code%22%3A%20%22BadRequest%22%2C%0A%20%20%20%20%22message%22%3A%20%22%7B%5Cr%5Cn%20%20%5C%22error%5C%22%3A%7B%5Cr%5Cn%20%20%20%20%5C%22code%5C%22%3A%5C%22UndefinedScope%5C%22%2C%5C%22message%5C%22%3A%5C%22Exception%20of%20type%20'Microsoft.Fast.Profile.Core.Exception.ProfileBadRequestException'%20was%20thrown.%5C%22%5Cr%5Cn%20%20%7D%5Cr%5Cn%7D%22%2C%0A%20%20%20%20%22innerError%22%3A%20%7B%0A%20%20%20%20%20%20%22date%22%3A%20%222021-06-01T10%3A52%3A35%22%2C%0A%20%20%20%20%20%20%22request-id%22%3A%20%2232aeff66-a806-4732-bbba-6872994ef2f7%22%2C%0A%20%20%20%20%20%20%22client-request-id%22%3A%20%2232aeff66-a806-4732-bbba-6872994ef2f7%22%0A%20%20%20%20%7D%0A%20%20%7D%0A%7D%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethis%20used%20to%20work%20for%20all%20users.%20our%20app%20is%20configured%20to%20accept%20%22Accounts%20in%20any%20organizational%20directory%20(Any%20Azure%20AD%20directory%20-%20Multitenant)%20and%20personal%20Microsoft%20accounts%20(e.g.%20Skype%2C%20Xbox)%22.%3CBR%20%2F%3E%3CBR%20%2F%3EThis%20works%20for%20professional%20accounts%20on%20my%20tenantid%2C%20but%20it%20doesn't%20work%20for%20personal%20account%20(tenantid%20%3CSPAN%20class%3D%22tabpanel-summary-value%20textbox-input%20devtools-monospace%22%3E9188040d-6c67-4c5b-b112-36a304b66dad%3C%2FSPAN%3E%20)%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3ECan%20you%20offer%20any%20advice%20%3F%20Thanks%20in%20advance%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2403489%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2414205%22%20slang%3D%22en-US%22%3ERe%3A%20400%20Bad%20Request%20UndefinedScope%20ProfileBadRequestException%20on%20%2Foidc%2Fuserinfo%20for%20some%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2414205%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1068232%22%20target%3D%22_blank%22%3E%40jonenst%3C%2FA%3E%26nbsp%3B%2C%20I%20had%20this%20same%20issue%2C%20and%20I%20found%20a%20workaround.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20used%20this%20end%20point%20instead%20to%20get%20the%20user%20info%2C%20and%20it%20worked%26nbsp%3B%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fgraph.microsoft.com%2Fv1.0%2Fme%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgraph.microsoft.com%2Fv1.0%2Fme%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20object%20returned%20is%20slightly%20different%20property%20name%20wise%2C%20but%20I'm%20able%20to%20get%20data%20from%20it%20with%20my%20personal%20account.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20this%20helps.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi,

our working setup stopped working sometime at the end of may (not sure of the exact date). We request a token from the authorization endpoint https://login.microsoftonline.com/<TENANT-ID>/oauth2/v2.0/authorize with the following scopes: "openid User.read profile"

 

we then issue a request to https://graph.microsoft.com/oidc/userinfo with the Authorization: Bearer <TOKEN> and get

 

{
  "error": {
    "code": "BadRequest",
    "message": "{\r\n  \"error\":{\r\n    \"code\":\"UndefinedScope\",\"message\":\"Exception of type 'Microsoft.Fast.Profile.Core.Exception.ProfileBadRequestException' was thrown.\"\r\n  }\r\n}",
    "innerError": {
      "date": "2021-06-01T10:52:35",
      "request-id": "32aeff66-a806-4732-bbba-6872994ef2f7",
      "client-request-id": "32aeff66-a806-4732-bbba-6872994ef2f7"
    }
  }
}

 

 

this used to work for all users. our app is configured to accept "Accounts in any organizational directory (Any Azure AD directory - Multitenant) and personal Microsoft accounts (e.g. Skype, Xbox)".

This works for professional accounts on my tenantid, but it doesn't work for personal account (tenantid 9188040d-6c67-4c5b-b112-36a304b66dad )

Can you offer any advice ? Thanks in advance

5 Replies

@jonenst , I had this same issue, and I found a workaround.

 

I used this end point instead to get the user info, and it worked  https://graph.microsoft.com/v1.0/me

 

The object returned is slightly different property name wise, but I'm able to get data from it with my personal account.

 

Hope this helps.

 

Hi, thanks for the reply. Nice to know I'm not the only one.

I just tested https://graph.microsoft.com/v1.0/me and indeed it returns my name and some other things.

 

However I can't use it because my code is not specific to azure's oidc provider. My code only gets the user_info endpoint from the  https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration document and uses that.

 

Do you know if I can report this to the team running "https://graph.microsoft.com/oidc/userinfo" ?

Thanks a lot

Hi, I am also facing the same issue recently, did you found any solution on this?. Thanks in advance.

@jonenst it sounds like this will need to be addressed on the Microsoft side if you're constrained by the values from the config document.

 

Unfortunately, I'm not aware of what the process to formally report it is.

 

Cheers,

 

Demetree

 

Testing again, it works now. apparently it was fixed this summer in their server.