IBM Support

IBM Datacap EWSMail using OAuth authentication service fail due to multi factor authentication.

Troubleshooting


Problem

To use OAuth authentication service provided by Azure Active Directory to enable EWS to access Exchange Online in Office 365, you will need to:

1) Register application with Azure Active Directory.
2) For Authentication, under "Default client type", set "Yes" to "Treat application as a public client."
3) For API permissions, add "Exchange - EWS.AccessAsUser.All" and grant consent."
Additional Problem can occur if Office365 force Multi Factor Authentication.

Symptom

When Multi Factor Authentication is enforced the follow error will show when ex_logon attempt are made.
09:52:06.979 (1156)    Error acquiring access token: MSAL.Desktop.4.7.1.0.MsalUiRequiredException:     ErrorCode: invalid_grant
Microsoft.Identity.Client.MsalUiRequiredException: AADSTS50076: Due to a configuration change made by your administrator, or because you moved to a new location, you must use multi-factor authentication to access '00000002-0000-0ff1-ce00-000000000000'.
 

Document Location

Worldwide

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSZRWV","label":"IBM Datacap"},"ARM Category":[{"code":"a8m50000000L0jSAAS","label":"troubleshooting"}],"ARM Case Number":"TS003874896","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)","Line of Business":{"code":"LOB76","label":"Data Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
08 September 2020

UID

ibm16245776