AADSTS65002 — First-party preauthorization not completing for new tenant
Nobody has claimed this yet.
- Dominant language
- PowerShell
- Stars
- 1k
- Forks
- 132
- Avg merge
- 5d 19h
- Merged PRs (30d)
- 6
Description
Environment: macOS, npx @microsoft/workiq v0.4.0
Tenant ID: 0a4f135c-c6da-4f4e-b12e-3981ff13d809
Account: matt@remotecoffee.com (Global Admin, Microsoft 365 Business Premium with Copilot license)
Problem: After provisioning a Copilot license ~24 hours ago, workiq ask fails with two errors:
AADSTS650052 — org lacks a service principal for app ea9ffc3e-8a23-4a7d-836d-234d7c7565c1 (Work IQ Tools)
Attempting admin consent returns AADSTS65002 — "Consent between first party application 'ea9ffc3e-8a23-4a7d-836d-234d7c7565c1' and first party resource '00000002-0000-0000-c000-000000000000' must be configured via preauthorization"
This indicates the preauthorization between the Work IQ first-party app and Microsoft Graph hasn't been configured for my tenant. Admin consent can't resolve this since it requires API-owner-side preauthorization.
Request ID: c2094359-9b87-4cf9-92fe-e9be3a3a7600
Correlation ID: 717a04ae-83a4-4a73-8795-e750336a6a3f
Timestamp: 2026-03-20T10:31:14Z
Expected: workiq ask authenticates and returns a response after Copilot license is active.
Question: Is there an additional provisioning step required, or does this need to be resolved on Microsoft's side?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the reported workiq ask failure with the AADSTS650052 and AADSTS65002 messages, using the request and correlation IDs when checking the provisioning path. Done means determining whether an additional tenant-side step exists or documenting that Microsoft-side preauthorization is required; no repository file or test is identified.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- node.js
- Domain
- api, authentication, cli
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100