entra1-6 Exercise 2: What Is Wrong and What Is Not ========================================================= Source: Microsoft Learn pages on permissions and consent, granting tenant-wide admin consent and app credentials. Re-check before relying on any detail. WHAT IS WRONG Gate 1, permissions and consent. The nightly sync job is an app-only (client credentials) job, so it uses APPLICATION permissions. The permission it needs, Microsoft Graph Directory.Read.All (Application), is requested by the application but has not been granted in Contoso's tenant. Without recorded consent, Entra refuses to issue a token carrying that permission. The error description ("not been granted the application permissions it requested") fits exactly. WHAT IS NOT WRONG - Credentials (Chapter 4): the client secret "prod 2026" expires 2027-06-30, so the secret is valid. The job reaches the token endpoint and fails on permissions, not on authentication. - The enterprise application is enabled for sign-in ("Enabled for users to sign in? = Yes"), so Chapter 5's master switch is not the cause. - Assignment (gate 2): "Assignment required? = No" and, anyway, the job is not a user. User.Read (Delegated) is granted for Contoso, so ordinary user sign-in works. - Conditions (gate 3): nothing in the extract suggests Conditional Access. WHAT TO ASK, AND OF WHOM Ask Contoso's administrator to review and grant admin consent for the application permission on Enterprise apps > Acme Reports > Permissions ("Grant admin consent"), after explaining what the job does with directory data and why Directory.Read.All is needed. Or send the tenant-wide admin consent URL: https://login.microsoftonline.com//adminconsent?client_id= Who can approve: for Microsoft Graph application permissions, Microsoft's page lists Privileged Role Administrator as able to grant consent for any permission, while Cloud Application Administrator and Application Administrator are excluded for Graph app roles (and Chapter 5's source adds that in practice this often means a Global Administrator). So the request may need to go up to someone more senior than the person you are talking to. Expect a security review: Directory.Read.All reads a lot of data, so a careful administrator may ask for a narrower permission. Your product team should know if one exists. WHY THIS WORKS AS AN ANSWER --- It separates the three gates, uses the evidence given (valid secret, enabled app, delegated permission fine, application permission not granted) and asks for one specific action by the right kind of approver.