SOLVED

c# and MicrosoftTeams PowerShell Modul 3.1.0

%3CLINGO-SUB%20id%3D%22lingo-sub-3074169%22%20slang%3D%22en-US%22%3Ec%23%20and%20MicrosoftTeams%20PowerShell%20Modul%203.1.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3074169%22%20slang%3D%22en-US%22%3E%3CP%3EHi!%3C%2FP%3E%3CP%3EI%20have%20a%20C%23%20program%20that%20uses%20the%20MicrosoftTeams%20PowerShell%20Modul%20to%20read%20policies%20etc.%3C%2FP%3E%3CP%3EIt%20did%20work%20well%20with%20Modul%20Version%202.6.1%3C%2FP%3E%3CP%3EAfter%20updating%20to%203.1.0%2C%20login%20via%20MFA%20doesn't%20work%20anymore%20(non-MFA%20still%20works).%3C%2FP%3E%3CP%3EPowerShell%20Error%3A%3C%2FP%3E%3CP%3EException%20%3D%20%7B%22Broker%20response%20returned%20error%3A%20WAM%20Error%20Wam%20plugin%20Microsoft.Identity.Client.Platforms.Features.WamBroker.AadPlugin%20Error%20code%3A%203399548929%20Error%20Message%3A%20Need%20user%20interaction%20to%20continue.%22%7D%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20WIndows%20Event%20Viewer%3A%3C%2FP%3E%3CP%3EError%3A%200xCAA2000C%20The%20request%20requires%20user%20interaction.%3CBR%20%2F%3ECode%3A%20interaction_required%3CBR%20%2F%3EDescription%3A%20AADSTS50078%3A%20Presented%20multi-factor%20authentication%20has%20expired%20due%20to%20policies%20configured%20by%20your%20administrator%2C%20you%20must%20refresh%20your%20multi-factor%20authentication%20to%20access%20'c5fde071-9440-4083-9e3c-b6712ad6e4d5'.%3CBR%20%2F%3ETrace%20ID%3A%20195be915-61f3-4dcc-a53a-70f455ce7200%3CBR%20%2F%3ECorrelation%20ID%3A%2049f54e0f-c928-46c2-b000-8bf1511383a7%3CBR%20%2F%3ETimestamp%3A%202022-01-27%2017%3A06%3A55Z%3CBR%20%2F%3ETokenEndpoint%3A%20%3CA%20href%3D%22https%3A%2F%2Flogin.microsoftonline.com%2Fcommon%2Foauth2%2Ftoken%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Flogin.microsoftonline.com%2Fcommon%2Foauth2%2Ftoken%3C%2FA%3E%3CBR%20%2F%3ELogged%20at%20OAuthTokenRequestBase.cpp%2C%20line%3A%20449%2C%20method%3A%20OAuthTokenRequestBase%3A%3AProcessOAuthResponse.%3C%2FP%3E%3CP%3ERequest%3A%20authority%3A%20%3CA%20href%3D%22https%3A%2F%2Flogin.microsoftonline.com%2Fcommon%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Flogin.microsoftonline.com%2Fcommon%3C%2FA%3E%2C%20client%3A%20ecd6b820-32c2-49b6-98a6-444530e5a77a%2C%20redirect%20URI%3A%20ms-appx-web%3A%2F%2FMicrosoft.AAD.BrokerPlugin%2Fecd6b820-32c2-49b6-98a6-444530e5a77a%2C%20resource%3A%20c5fde071-9440-4083-9e3c-b6712ad6e4d5%2C%20correlation%20ID%20(request)%3A%2049f54e0f-c928-46c2-b000-8bf1511383a7%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20ideas%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance%2C%20Joerg%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3074169%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMicrosoft%20Teams%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3080579%22%20slang%3D%22en-US%22%3ERe%3A%20c%23%20and%20MicrosoftTeams%20PowerShell%20Modul%203.1.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3080579%22%20slang%3D%22en-US%22%3EWe%20are%20looking%20into%20this%20issue.%20We%20will%20update%20you.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3092573%22%20slang%3D%22en-US%22%3ERe%3A%20c%23%20and%20MicrosoftTeams%20PowerShell%20Modul%203.1.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3092573%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20got%20an%20update%20from%20the%20engineering%20team%20saying%20-%20%3CBR%20%2F%3EMFA%20is%20supported%20only%20with%20interactive%20option%2C%20Please%20refer%20-%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Fmodule%2Fteams%2Fconnect-microsoftteams%3Fview%3Dteams-ps%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Fmodule%2Fteams%2Fconnect-microsoftteams%3Fview%3Dteams-ps%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-contrast%3D%22none%22%3EThanks%2C%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EMeghana%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-contrast%3D%22none%22%3E---------------------------------------------------------------------------------------------------------%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-contrast%3D%22none%22%3EIf%20the%20response%20is%20helpful%2C%20please%20click%20%22**Mark%20as%20Best%20Response**%22%20and%20like%20it.%20You%20can%20share%20your%20feedback%20via%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FDevSupportFeedback)%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSPAN%20data-contrast%3D%22auto%22%3EMicrosoft%20Teams%20Developer%20Feedback%3C%2FSPAN%3E%3C%2FA%3E%3CSPAN%20data-contrast%3D%22none%22%3E%26nbsp%3Blink.%20Click%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FDevCommunityEscalationForm%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSPAN%20data-contrast%3D%22auto%22%3Ehere%3C%2FSPAN%3E%3C%2FA%3E%3CSPAN%20data-contrast%3D%22none%22%3E%26nbsp%3Bto%20escalate.%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3094053%22%20slang%3D%22en-US%22%3ERe%3A%20c%23%20and%20MicrosoftTeams%20PowerShell%20Modul%203.1.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3094053%22%20slang%3D%22en-US%22%3EWhat%20-%20excatly%20-%20do%20they%20mean%20with%20%22interactiv%20option%22%3F%20Where%20can%20I%20set%20such%20an%20option%3F%3CBR%20%2F%3EWhen%20you%20connect%20to%20Azure%20AD%20or%20Exchange%20with%20an%20MFA%20enabled%20account%2C%20the%20interactive%20Logon%20Windows%20pops%20up%20and%20you%20can%20log%20on%20interactively%20(same%20behavior%20in%20ISE%20and%20C%23).%20When%20you%20do%20the%20same%20with%20Teams%2C%20PowerShell%20throws%20the%20error%20mentioned%20above.%20So%20the%20behavior%20of%20the%20Teams%20Modul%20is%20not%20consistent%20with%20AAD%20or%20Exchange.%3CBR%20%2F%3EBy%20the%20way%3A%20if%20you%20issue%20the%20command%20in%20ISE%20directly%2C%20it%20works%20even%20with%20Teams.%20If%20you%20issue%20the%20same%20command%20via%20C%23%2C%20it%20doesn't%20work.%3C%2FLINGO-BODY%3E
New Contributor

Hi!

I have a C# program that uses the MicrosoftTeams PowerShell Modul to read policies etc.

It did work well with Modul Version 2.6.1

After updating to 3.1.0, login via MFA doesn't work anymore (non-MFA still works).

PowerShell Error:

Exception = {"Broker response returned error: WAM Error Wam plugin Microsoft.Identity.Client.Platforms.Features.WamBroker.AadPlugin Error code: 3399548929 Error Message: Need user interaction to continue."}

 

In WIndows Event Viewer:

Error: 0xCAA2000C The request requires user interaction.
Code: interaction_required
Description: AADSTS50078: Presented multi-factor authentication has expired due to policies configured by your administrator, you must refresh your multi-factor authentication to access 'c5fde071-9440-4083-9e3c-b6712ad6e4d5'.
Trace ID: 195be915-61f3-4dcc-a53a-70f455ce7200
Correlation ID: 49f54e0f-c928-46c2-b000-8bf1511383a7
Timestamp: 2022-01-27 17:06:55Z
TokenEndpoint: https://login.microsoftonline.com/common/oauth2/token
Logged at OAuthTokenRequestBase.cpp, line: 449, method: OAuthTokenRequestBase::ProcessOAuthResponse.

Request: authority: https://login.microsoftonline.com/common, client: ecd6b820-32c2-49b6-98a6-444530e5a77a, redirect URI: ms-appx-web://Microsoft.AAD.BrokerPlugin/ecd6b820-32c2-49b6-98a6-444530e5a77a, resource: c5fde071-9440-4083-9e3c-b6712ad6e4d5, correlation ID (request): 49f54e0f-c928-46c2-b000-8bf1511383a7

 

Any ideas?

 

Thanks in advance, Joerg

6 Replies
We are looking into this issue. We will update you.

We got an update from the engineering team saying -
MFA is supported only with interactive option, Please refer - https://docs.microsoft.com/en-us/powershell/module/teams/connect-microsoftteams?view=teams-ps

 

Thanks, 

Meghana

---------------------------------------------------------------------------------------------------------

If the response is helpful, please click "**Mark as Best Response**" and like it. You can share your feedback via Microsoft Teams Developer Feedback link. Click here to escalate. 

What - excatly - do they mean with "interactiv option"? Where can I set such an option?
When you connect to Azure AD or Exchange with an MFA enabled account, the interactive Logon Windows pops up and you can log on interactively (same behavior in ISE and C#). When you do the same with Teams, PowerShell throws the error mentioned above. So the behavior of the Teams Modul is not consistent with AAD or Exchange.
By the way: if you issue the command in ISE directly, it works even with Teams. If you issue the same command via C#, it doesn't work.
best response confirmed by joergsc_4711 (New Contributor)
Solution

@joergsc_4711 - The engineering team has ran command in C# for a test tenant with MFA enabled and it is working fine in  version 3.1.1. Sharing the script and the output.

Script :

MeghanaMSFT_0-1644240167480.jpeg

Output :

MeghanaMSFT_1-1644240183512.png

 

Can you please update version and try again? And if failing again please share the complete screenshot of error and script?

@Meghana-MSFT - YES. That works. The difference is the -AccountId Parameter.
My original statement was ...AddCommand("Connect.MicrosoftTeams -AccountId Email address removed")
Then PowerShell returns with error: "Broker response returned error: WAM Error Wam plugin Microsoft.Identity.Client.Platforms.Features.WamBroker.AadPlugin Error code: 3399548929 Error Message: Need user interaction to continue."
If you omit the -AccountId Parameter, it works.
This is different from AzureAd Modul. There you can specify the -AccountId Parameter to prepopulate the interactive MFA Login Window.
Without your screenshot it would have taken ages to find this.
So: many thanks!!

@joergsc_4711 - 

If the response is helpful, please click "**Mark as Best Response**" and like it. You can share your feedback via Microsoft Teams Developer Feedback link. Click here to escalate.