When appropriate to NOT have a resourceID parameter in AADSTS token request?

the Azure API Manager web app (a web service proxy) has a developer console - that makes oauth2 calls to AAD just fine. Up pops a browser windows that concludes authorization, and the web app attempt to convert code to token.
AADSTS rejects the request, objecting to the lack of resource parameters, in the posted parameter set.
MSDN markets the resource parameter as optional.
So how does one configure an AAD app so that the consuming app does NOT need to nominate the resource?
Essentially, the app is a classical oauth2 webapp, acting as a confidential client, having a clientid/clientsecret credentials and the redirect secret.
This use of api manager to send oauth2 request is NOT related to a similar oauth2 integration between APIM and AAD, in which one logs into the developer web app itself, using an openid connect flows.

Greetings, Peter!
Please confirm if you are talking about the “Resource” Parameter in an OAuth flow. Could you please share the MSDN documentation you are referring to which states the use of “Resource” Parameter as optional?
If it’s OAuth flow (which is likely looking at your question), then this is what Resource parameter is being used for:
Resource parameter depicts the identifier of the WebAPI that your client wants to access on behalf of the user. Most flows in OAuth involve 4 parties, the resource owner (aka user), the client (aka app), the authority (aka identity provider) and the resource
(aka webapi). The audience of the access token that the authority generates is the resource identifier.
In the case of Azure AD, you can either use the Client ID or the App ID URI of the resource WebAPI (Find them in the configure tab of the Azure AD application in the Azure Management portal). For instance, if I want my client to get a token
to access the Azure AD Graph API on behalf of the user, I would request for a token for resource "https://graph.windows.net".
Thank you,
Arvind

Similar Messages

  • Asking the Bridge Team:  Bridge "working color space" setting when one does not have the Suite?

    Common sense tells me there is really no such thing as a
    "working color space" in Bridge, because
    Bridge is not an image editor, just a browser
    Therefore, this may turn out to be a purely academic question; but that doesn't keep my curiosity from forcing me to ask it anyway. ;)
    Is there a way to set the Bridge
    "color settings" when one does not have the suite?
    The only Adobe program I keep up to date is Photoshop, so I've never had the suite. My version of Photoshop is 11 (CS4) and I run updated
    (not upgraded) versions of Adobe Acrobat 7.x, Illustrator 10.x and InDesign 2.x. Consequently, the Synchronize color settings command is not available to me.
    It seems to me that Bridge is behaving like a proper color-managed browser (e.g. Firefox with color management enabled), in that it displays tagged image files correctly and assumes sRGB for untagged image files. This normally works fine.
    But what if I wanted Bridge to assume my
    Photoshop color working space for untagged images
    so that it behaves the same as Photoshop? I'm just curious, as I deal with a minuscule, practically negligible amount of untagged files.
    My reason for bringing it up now is that I don't recall this being explicitly mentioned in forum replies when users inquire about color settings in Bridge. A recent post regarding Version Cue in the Photoshop Macintosh forum got me thinking about this. Just wanting to make sure that I'm right in my assumption that
    there is really no such thing as a
    "working color space" in Bridge, because Bridge is not an image editor, just a browser.
    Thanks in advance.

    Hi Ramón,
    Thanks for sharing the outcome of your tests. However, I may have found a bug/exception to Bridge's colour management policy!
    It appears that CMYK EPS photoshop files are not colour managed in Adobe Bridge, even if they contain an embedded ICC profile.
    I've tried every combination in the EPS 'Save As' dialogue box, so it doesn't seem to be an issue with file encoding. Also, Bridge doesn't rely on the low-res preview that is held within the EPS itself.
    My guess is that Bridge is previewing the CMYK EPS with a Bridge-generated RGB image, but it's being displayed as monitor RGB (assigned) rather than colour managed (converted to monitor RGB). For most users the difference will be barely perceptible, but the problem became very noticeable when using Bridge to preview Newsprint CMYK images on a wide-gamut monitor (images that should have appeared muted really leapt off the screen!).
    How do I report this to the Colour Police at Adobe?!?

  • Quota deduction when EE has been inactive for more than 180 days / Advance quota days when employee does not have enough balance

    Dear experts,
    We have two requirements regarding to the "Anual leave" quota.
    1. Quota reduction when employee is inactive for more than 180 days
    2. Advance quota days when employeee does not have enough balance
    We have in place an "Anual Leave" quota related to a calendar year period, that gets generated dialy in time evaluation. This quota gets the employee entitlement from a set of rules that stored the corresponding balance in a period time type, that is the one that we defined in the customizing. This is working fine. The problems start when we try to incorporate the other two requirements.
    Regarding the first requirement, if the employee has been inactive for more than 180 days in a calendar year due to unpaid leave, we need to start quota reduction as follow,
    First, we need to clear the balance that was calculated above in the schema.
    Then, we need to calculate one leave day for every 20 days worked till the end of the year, considering as such, everyday the employee is expected to work, except days on which the employee has been absent on unpaid leave.
    For the second requirement we created a manual quota call "Advance Anual Leave". So, if the employee, wishes to take 20 working days holiday, but in his/her Anual Leave quota has only 10 days available, we have to create an "Advance Anual Leave" quota manualy for 10 days. When the quota for next year gets generated, we need to deduct these advanced 10 days from it. This deduction should stop the year after.
    The problem we are finding with these two requirements is that, due to the Anual Leave quota gets generated dialy, we can't get the balance right.
    Thanks in advance!
    Kind regards,
    Alex

    Hello binbingogoABC,
    Shopping on BestBuy.com should be easy and fun and not fraught with the kind of trouble that you describe. I regret very much that this has been your experience.
    Using the information you provided when you signed up for Best Buy Unboxed I was able to locate your cancelled orders. I have requested more information from my back-office partners. As soon as I have additional details about your situation, I will reply again to this message. In the interim, I'm sorry that I must impose upon your patience.
    I'm very grateful that you wrote to us with your concerns.
    Sincerely,

  • How do I change an old iCloud I'd when I do not have access to that email anymore?

    How do I change an iCloud ID when I do not have the email account anymore and i do not remember the password?

    If your device is signed into an old ID of yours that is an earlier version of the ID you want to sign in with, do the following:
    If you are using iMessage and FaceTime, make sure you are signed into these services with your current ID.  If they are signed into the old ID, go to Settings>Messages>Send & Receive and Settings>FaceTime, tap the ID, sign out, then sign back in with your current ID.
    Then temporarily recreate the old ID by going to https://appleid.apple.com, click Manage my Apple ID and sign in with your current iCloud ID.  Click edit next to the primary email account, change it back to your old email address and save the change.  (You should not have to verify the old email account so it doesn’t matter if you no longer have access to it.)  Now go to Settings>iCloud, turn off Find My iDevice and enter your current password when prompted (even though it prompts you for the password for your old ID).  Then save any photo stream photos that you wish to keep to your camera roll (unless you are using iCloud Photo Library).  When finished go to Settings>iCloud, tap Sign Out (or Delete Account if you are not running iOS 8) and choose Delete from My iDevice when prompted (your iCloud data will still be in iCloud).  Next, go back to https://appleid.apple.com and change your primary email address back to the way it was.  Now you can go to Settings>iCloud and sign back in with your current iCloud ID and password (your data will download back to your device).

  • Why is HP SimplePass on my new windows 8.1 machine, when I do not have a finger or card reader?

    Why is HP SimplePass on my new windows 8.1 machine, when I do not have a finger print or card reader?
    It keeps popping up and asking me to use it?
    Can it be used to keep my passwords?
    What Version of SimplePass are you using?   Unknown, apparently you have to use it to find the version number.
    What is your Operating System? Windows 7 32 or 64bit? or?   Windows 8.1  64 Bit
    Which browser are you using?  Internet explorer version 11, and Fire fox version 34.0
    Can you give me a example of a Website that is giving you this problem?  Have not used it yet.
    Is is every webcard or just one or two websites that have this problem?  Have not used it yet
    What is your computer product number? (NOT serial number?)  HP 15-f039wm Notebook PC
    Thanks for any help you can offer.

    Hi,
    You could check the blog below.
    How to Enable Group Policy Debugging on Windows 7 / 8 Clients
    http://clintboessen.blogspot.jp/2014/01/how-to-enable-group-policy-debugging-on.html
    Note: Microsoft provides third-party contact information to help you find technical support. This contact
    information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.
    If you have any questions about Group Policy, you could get better support from Group Policy forum.
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/home?forum=winserverGP
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • HI, I need your help. How can I delete all data, when I do not have the special security code, which I didn´t remember ? I also think, that I never create this code before. But I cannot put my settings back.

    HI, I need your help. How can I delete all data, when I do not have the special security code, which I didn´t remember ? I also think, that I never create this code before. But I cannot put my settings back.

    You must remember the code, if you can't then take the phone and proof of purchase to an Apple Store.

  • How do I get twitter installed on my iPad when it does not have iOS 5.0?

    How do I get twitter installed on my iPad when it does not have iOS 5.0? How can I upgrade my iPad?

    If you have an iPad 1, the max iOS is 5.1.1. For newer iPads, the current iOS is 6.1. The Settings>General>Software Update only appears if you have iOS 5.0 or higher currently installed.
    iOS 4: Updating your device to iOS 5 or Later
    http://support.apple.com/kb/HT4972
    How to install iOS 6
    http://www.macworld.com/article/2010061/hands-on-with-ios-6-installation.html
    iOS: How to update your iPhone, iPad, or iPod touch
    http://support.apple.com/kb/HT4623
    If you are currently running an iOS lower than 5.0, connect the iPad to the computer, open iTunes. Then select the iPad under the Devices heading on the left, click on the Summary tab and then click on Check for Update.
    Tip - If connected to your computer, you may need to disable your firewall and anitvirus software temporarily.  Then download and install the iOS update. Be sure and backup your iPad before the iOS update. After you update an iPad (except iPad 1) to iOS 6.x, the next update can be installed via wifi (i.e., not connected to your computer).
     Cheers, Tom

  • I have an ipod touch 4g. I did not have wifi for three days and when I came home my friends said they texted me when i didnt have signal. The messages i received when i did not have signal are not showing up. Can someone please help me?

    I have an ipod touch 4g. I did not have wifi for three days and when I came home my friends said they texted me when i didnt have signal. The messages i received when i did not have signal are not showing up. Can someone please help me?

    You said "The messages i received when i did not have signal are not showing up."
    How do you know received them?
    If the sender got a message that the Messagers were not delivered than they were never delivered and the only way for you to get them is for the sender to resent them

  • Why does Firefox give this message when I do not have another program running "Firefox is already running, but is not responding. To open a new window, you must first close the existing Firefox process, or restart your system."

    Question
    why does Firefox give this message when I do not have another program running or another window open - "Firefox is already running, but is not responding. To open a new window, you must first close the existing Firefox process, or restart your system." edit

    See also "Hang at exit":
    *http://kb.mozillazine.org/Firefox_hangs
    *https://support.mozilla.com/kb/Firefox+hangs

  • 1 unread message, when I do not have have any unread messages

    The email icon on my iphone 4gs, os6 indicates that I have one unread message, when in fact I do not have any new messages. I have tried to restore, power down, reset and it keeps indicating I have a new message. When I do not have any unread messages... can someone help?
    Thanks

    See also "Hang at exit":
    *http://kb.mozillazine.org/Firefox_hangs
    *https://support.mozilla.com/kb/Firefox+hangs

  • When you do not have Digital How To MAKE unlock iphone 5s?

    when you do not have Digital How To MAKE unlock iphone 5s?

    In the Finder, press the key combination shift-command-C, or select
              Go ▹ Computer
    from the menu bar. A window will open showing all mounted volumes. Select the one in question and open the Info window. What is shown as the Format in the General section?

  • How to capture SOAP fault when using "Do not use SOAP envelope" parameter

    Hi,
    we have a synchronous  RFC -> XI -> Web Service scenario. The Web Service requires some custom SOAP header elements for user authorization which forced us create the entire SOAP message in a message mapping and to set the "Do not use SOAP envelope" parameter in the receiving SOAP adapter.
    In order to capture the SOAP fault message from the Web Service we have created a message interface with a fault message and also created an interface mapping with a fault message mapping.
    Our problem is that the fault message is not populated when we get a SOAP fault message back from the Web Service. Is this due to the fact that we have set the  "Do not use SOAP envelope" parameter?
    Thanks in advance!
    Stefan
    Message was edited by:
            Stefan Nilsson

    Hi Bhavesh,
    I have exaactly same scenario. But the only difference is that the Successful payload is also not coming into PI.
    The request is successfully hittng the webservice.
    Please guide me on how to capture the paylod.
    I am using the WSDL provided by the thirdparty but sill the message is not coming into PI.

  • How to create a "Firefighter" type role when we do not have GRC

    I am just looking for advice or input on this situation.
    Currently my company does not have GRC or any other type of software that will allow for automated Firefighter type access and apparently there are no plans in the near future to purchase anything.
    Our current process of creating a very powerful role to sign out to users on a case by case basis for a 24 hour period is not working and is getting out of hand.
    I have been tasked with coming up with a better solution and they want me to build multiple roles for emergency access based on business area. Since there are thousands of transaction codes in SAP I find this to be a rather daunting task. My question is this...would it be a really bad idea to build say a Finance emergency role with F* in s_tcode and full access? I realize that there are more Finance codes that do not start with F but I am really just looking for input.
    Has anyone else faced this situation and how did you approach it?
    If someone out there has done this and could provide me with sample roles, that would be great.
    Any help or advice is greatly appreciated.
    Thanks
    Bobbi

    Hi Bobbi
    There are couple of ways I did it in my previous customers. I am guessing you need these roles during Go-Live and Production Support
    1. Create FF roles by business Process ( OTC, RTR etc) or Module wise. Get hold of the respective Functional people and ask them the nodes in SPRO Tcode what they think should be there for those FF roles. Then create those roles accordingly. Remove the Basis / Security admin tcodes and make 03 where-ever necessary.
    2. Another way of doing it is you might already have global roles for different modules / business processes. So identify the roles that are best suited for the FF roles and during Go-Live/ Prod Support. Group them and may be create composite roles for those Global single roles
    You might need FF roles for Transactional access and Configuration Access.
    Transactional FFID: FFID with change access to business transactions of the stream/function. (Can use the create/change access roles built for end users)
    Configuration FFID: FFID for any manual configu2019s to be performed directly in production and cannot/may not be transported (ex: number ranges)
    There should be process for giving the FF roles and proper approval. Appropriate role owners should be identified for these roles who will give approval
    Hope this helps

  • Why attribute chnage run is needed when u do not have aggregates?

    Hi,
    Attribute change run is needed soon after the hierarchy upload is understandable!
    Attribute change run is needed soon after the Transactional data also if the cube has aggreagtes is also understandable!
    But my cube does not have any aggreagtes created and it is a new one by far!
    even then in my process chain, soon sfter i add the infopackage process, i am getting the attribute change run automatically in the process chain!
    Can any body explain me why i am getting that attribute change run after the trasactional IP though that does not have any aggregates!
    Thanks,
    Ravi

    hi ravi,
    up to my knowledge, activation is enough if no aggregates are manitained.
    refer the following text.
    Activating Master Data and Texts
    Prerequisites
    Master data and texts have already been loaded into the BI system using the scheduler.
    Procedure
    Activating Master Data
    When you update master data from an SAP system the master data is imported in an inactive state. You must activate the new master data so that it can be accessed and used for reporting purposes.
    For more information, see Versioning Master Data.
    Choose the path InfoObject Tree ® Context Menu of Corresponding Characteristic  ® Activate Master Data.
    Upon Activation there are two scenarios to choose from:
    The Corresponding Master Data Is Already Being Used in Aggregates in the InfoCube:
    If you are already using the available master data in aggregates in InfoCubes, you cannot activate the master data individually. In this case, proceed as follows:
           1.      In the main menu, choose the path Tools ®Hierarchy/Attribute Change.
           2.      Proceed as described in System Response upon Changes to Data: Aggregate.
    The system now automatically restructures and activates the master data and its aggregates.
    Please note that this process can take several hours if the volume of data is relatively high. Therefore, you should simultaneously activate all of the characteristics that are affected by changes to their master data, at regular intervals.
    The Corresponding Master Data Is Not Used in Aggregates:
    Choose the path InfoObject Tree ® Context Menu of Corresponding Characteristic  ® Activate.
    The system now automatically activates the master data so that it can be used directly in reporting.
    Activating Texts
    Texts are active immediately and can be used directly in reporting. You do not need to Activate manually.
    thank u,
    reward if helpful.

  • How to download flash player when computer does not have a password?

    I am trying to update flash player on my Mac. I do not have a password for this computer. I have done updates before, and just ignored the box where it asks for password. Now, when I ignore this box, I can't go forward. What can I do?

    If you have set a blank Administrator password, then the install should go forward with the blank password.
    If not, then I would assume it to be a problem with your operating system.  Contact Apple.
    [topic moved to Flash Player forum]

Maybe you are looking for

  • Can i put my itunes library on an external disk?

    hi, i want to store my itunes library on and external disk but want it to work just like it does on the internal hdd. is that possible? i tried to store it on a home server. and while i could play the contents of the library. the art-work and so-fort

  • Music not showing up on ipod, but memory is used up

    i have a 4G nano, and when i plug it into itunes it shows that there isn't any music on my ipod, but it reads that all the memory is used up. do i need to reset or restore to original settings?

  • Company code details

    i need company code tax details where i have to mentioned in sap like company code cst number,lst number, vat number these details wheir i will mentioned and please give me these table  & fields

  • PLD Problem

    How to pick Customer Details in Purchase Order like Address, TIN No, CST No.............., ETC.

  • Blackberry Assistant, function and features

    When using the blackberry Assistant to dictate a E-mail or message, is it possible to insert a line break? Also is it possible to control or adjust the punctuation being inserted/use? For example, when you say double quote the assistant inserts the H