Ein Azure-Netzwerksicherheitsdienst zum Schutz von Azure Virtual Network-Ressourcen.
OAuth2-Tokenabruf per client_credentials von dediziertem Linux-Server scheitert mit sofortigem HTTP 404 vom Microsoft Gateway
Hallo, Wir versuchen, für unsere Anwendung ein OAuth2-Token über den client_credentials-Flow zu beziehen. Die Anforderung wird von unserem dedizierten Linux-Server bei IONOS in Deutschland gesendet.
Die Anfrage an den Microsoft Entra Token-Endpunkt wird jedoch sofort mit HTTP/1.1 404 Not Found beantwortet. Das Verhalten tritt direkt am Gateway auf und sieht nicht wie ein normaler OAuth- oder Anwendungsfehler aus.
Die identische Anfrage funktioniert erfolgreich, wenn sie aus einem lokalen Clientnetzwerk ausgeführt wird. Das Problem ist daher an die öffentliche Quell-IP unseres Servers gebunden.
Ziel-URL
https://login.microsoftonline.com/<my-tenant-id>/oauth2/v2.0/token
Beobachtetes Verhalten
Sofortiges HTTP 404 Not Found
Antwort kommt direkt vom Microsoft Gateway
Die gleiche Anfrage funktioniert aus einem anderen Netzwerk
Zeitpunkt des Fehlers
Thu, 06 Aug 2026 14:46:20 GMT
Diagnosedaten
client-request-id: 83c50176-5593-402d-b158-2416d4165fdf
x-ms-gateway-slice: estsfd
PS: Die gewählten Tags sind möglicherweise nicht zutreffend
Azure Firewall
-
Harshitha Eligeti • 4,530 Zuverlässigkeitspunkte • Externe Microsoft-Mitarbeiter • Moderator
2026-08-09T21:14:44.62+00:00 Hello @Nasgol Bakhtiari
Thank you for the additional details.Based on the information provided, an immediate HTTP 404 Not Found response returned directly by the Microsoft Gateway, while the identical request succeeds from a different network, suggests that the application configuration and client credentials are likely valid. The behavior appears to be network-specific and may be related to DNS resolution, proxy configuration, firewall inspection, request modification, or routing from the affected environment.
To further investigate, please help us with the following:
Verify that the token endpoint URL is correctly formatted and accessible from the affected Linux server.
https://login.microsoftonline.com/<tenant-id>/oauth2/v2.0/tokenTest access to the OpenID configuration endpoint from the same server and share the results.
curl -v https://login.microsoftonline.com/<tenant-id>/v2.0/.well-known/openid-configurationCompare DNS resolution results between the affected server and a network where the request succeeds.
nslookup login.microsoftonline.comIf a proxy, WAF, firewall, or SSL inspection device is present, review its logs to determine whether the request is being modified or redirected before reaching Microsoft services.
Capture and share verbose output from the request (with sensitive information removed), including the complete response headers.
curl -vvv -X POST <token-endpoint>Additionally, please provide:
- The public source IP address of the affected server.
- The full HTTP response headers associated with the 404 responses.
- Any proxy or network security devices present in the outbound path.
This information will help determine whether the request is reaching the Microsoft Entra endpoint as expected or whether the traffic is being altered before it arrives at the service.
References: Troubleshooting-signature-validation-errors
v2-oauth2-client-creds-grant-flowWe look forward to your update.
-
Nasgol Bakhtiari • 35 Zuverlässigkeitspunkte
2026-08-11T14:31:28.6766667+00:00 Hi, many thanks for your response. following is the curl call from affected server.
curl -v -X POST "https://login.microsoftonline.com/18a94d4e-931b-4393-86da-76f0015f6990/oauth2/v2.0/token" -H "Content-Type: application/x-www-form-urlencoded" -d "client_id=48af8abd-275a-4bc5-b753-56df254b63c9" -d "client_secret=<mysecret>" -d "scope=https://graph.microsoft.com/.default" -d "grant_type=client_credentials"
Note: Unnecessary use of -X or --request, POST is already inferred.
- Host login.microsoftonline.com:443 was resolved.
- IPv6: (none)
- IPv4: 40.126.32.68, 40.126.32.138, 40.126.32.74, 20.190.160.132, 20.190.160.14, 40.126.32.72, 40.126.32.140, 20.190.160.2
- Trying 40.126.32.68:443...
- ALPN: curl offers h2,http/1.1
- TLSv1.3 (OUT), TLS handshake, Client hello (1):
- CAfile: /etc/ssl/certs/ca-certificates.crt
- CApath: /etc/ssl/certs
- TLSv1.3 (IN), TLS handshake, Server hello (2):
- TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
- TLSv1.3 (OUT), TLS handshake, Client hello (1):
- TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):
- TLSv1.3 (IN), TLS handshake, Server hello (2):
- TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
- TLSv1.3 (IN), TLS handshake, Certificate (11):
- TLSv1.3 (IN), TLS handshake, CERT verify (15):
- TLSv1.3 (IN), TLS handshake, Finished (20):
- TLSv1.3 (OUT), TLS handshake, Finished (20):
- SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / secp384r1 / RSASSA-PSS
- ALPN: server did not agree on a protocol. Uses default.
- Server certificate:
- subject: C=US; ST=Washington; L=Redmond; O=Microsoft Corporation; CN=stamp2.login.microsoftonline.com
- start date: Jun 12 00:00:00 2026 GMT
- expire date: Dec 9 23:59:59 2026 GMT
- subjectAltName: host "login.microsoftonline.com" matched cert's "login.microsoftonline.com"
- issuer: C=US; O=DigiCert Inc; CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1
- SSL certificate verify ok.
- Certificate level 0: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption
- Certificate level 1: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption
- Certificate level 2: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption
- Connected to login.microsoftonline.com (40.126.32.68) port 443
- using HTTP/1.x
POST /18a94d4e-931b-4393-86da-76f0015f6990/oauth2/v2.0/token HTTP/1.1
Host: login.microsoftonline.com
Accept: /
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)
Content-Type: application/x-www-form-urlencoded
Content-Length: 174
- upload completely sent off: 174 bytes
- TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
< HTTP/1.1 404 NotFound
< Content-Type: text/HTML
< Set-Cookie: x-ms-gateway-slice=estsfd; path=/; secure; samesite=none; httponly
< client-request-id: 1dfdf13c-cc00-4c28-a6df-7d1ef7f25010
< Date: Mon, 10 Aug 2026 18:37:02 GMT
< Content-Length: 10
<
- Connection #0 to host login.microsoftonline.com left intact
-
Nasgol Bakhtiari • 35 Zuverlässigkeitspunkte
2026-08-11T14:32:57.7733333+00:00 Title:
HTTP 404 NotFound at the Entra OAuth2 token endpoint only from public IP 212.227.203.51 during client_credentials flow
Description:
We are consistently receiving HTTP/1.1 404 NotFound when requesting an OAuth2 token through the client_credentials flow from our dedicated Linux server with public IP 212.227.203.51 against the Microsoft Entra token endpoint:
https://login.microsoftonline.com/18a94d4e-931b-4393-86da-76f0015f6990/oauth2/v2.0/token
The identical raw request succeeds from a different network and returns HTTP/1.1 200 OK with a JSON response.
Behavior from the affected server:
- HTTP/1.1 404 NotFound
- Content-Type: text/HTML
- Content-Length: 10
- Response body: Not Found.
- x-ms-gateway-slice=estsfd
Example identifiers:
- client-request-id: dc2906c1-5447-416f-ae1f-ca665186bec4
- client-request-id: 1dfdf13c-cc00-4c28-a6df-7d1ef7f25010
- client-request-id: 83c50176-5593-402d-b158-2416d4165fdf
Example timestamps:
- 11 Aug 2026 12:49:47 GMT
- 10 Aug 2026 18:37:02 GMT
- 06 Aug 2026 14:46:20 GMT
Checks already completed:
- DNS resolution for login.microsoftonline.com is correct
- TLS handshake succeeds
- Certificate is valid and issued to Microsoft
- No local proxy is configured, and testing with --noproxy '*' still fails
- No difference between HTTP/1.1 and HTTP/2
- Different User-Agent tests had no impact
- Request path, host, Content-Type, Content-Length, and request body are effectively identical between the working and failing traces
- No sign-in logs are generated in the tenant for these failed requests
Technical assessment:
The request reaches Microsoft edge successfully, but for the affected source IP it is terminated before normal Entra token processing with a generic HTML 404 response. Because the exact same raw request is processed successfully from another network, the evidence strongly suggests a source-IP-specific edge, routing, or access issue, or a very early service-side behavior before normal Entra authentication logic is reached.
Please investigate a source-IP-specific issue affecting public IP 212.227.203.51 when accessing the token endpoint above.
-
Nasgol Bakhtiari • 35 Zuverlässigkeitspunkte
2026-08-14T08:01:48.4966667+00:00 Hello, I would like to know how to open a support ticket regarding a blocked IP address. Thank you for your reply.
-
Nasgol Bakhtiari • 35 Zuverlässigkeitspunkte
2026-08-19T06:37:38.1+00:00 Hello, is there any chance to get support here?
-
Harshitha Eligeti • 4,530 Zuverlässigkeitspunkte • Externe Microsoft-Mitarbeiter • Moderator
2026-08-19T19:00:42.1+00:00 Hello @Nasgol Bakhtiari
We have initiated Private message to gather some details, could you please review the details and help us with the requested information to proceed further. -
Nasgol Bakhtiari • 35 Zuverlässigkeitspunkte
2026-08-24T08:25:56.8466667+00:00 Hello @Harshitha Eligeti
thank you for your response. As i wrote to you via private message, there is no ticket. Because the Self Service Support does not allow me to create one. Every time i try, get redirected to PCS. That is poor support, I wonder what I'm even paying a support fee for.
-
Jan Eberhage | dgp • 0 Zuverlässigkeitspunkte
2026-09-01T23:20:53.9433333+00:00 Hello,
i want to add that our tenant has the exact same problem described here.
I always get 'Not found' when i POST to "https://login.microsoftonline.com/common/oauth2/v2.0/token" from our IONOS server (IP: 82.165.82.156)
POSTing from my private linux server is no problem.
Please fix this.
-
Nasgol Bakhtiari • 35 Zuverlässigkeitspunkte
2026-09-06T15:15:18.1466667+00:00 Hello @Harshitha Eligeti , hello @Jan Eberhage | dgp i reopened the support request (ID: 2608250050001572) on portal.azure.com. It was simply closed after 9 days without a solution and without any communication with me. Unbelievable.
-
Guido Meyer • 0 Zuverlässigkeitspunkte
2026-09-07T18:41:31.9766667+00:00 Hey,
ich habe genau das gleiche Problem mit einem dedizierten Server von United-Domains. Es kommt exakt die gleiche Abweisung beim oauth2 Token. Witzigerweise habe ich das auch erst seid ein paar Tagen, davor hat es noch Reibungslos funktioniert.
@Nasgol Bakhtiari hast du hier noch etwas gehört?
VG
-
Nasgol Bakhtiari • 35 Zuverlässigkeitspunkte
2026-09-08T11:19:58.7266667+00:00 Hallo @Guido Meyer die Mitarbeiter von MS Support hatten versucht mich zu kontaktiert, ich war aber leider wegen Krankheit nicht erreichbar, deswegen haben sie das Support Ticket geschlossen. Ich habe es wieder geöffnet und hoffe auf baldige Rückmeldung. Ich teile hier meine Erfahrung und möglicherweise auch die Lösung sobald das Problem behoben ist.
VG
Zum Kommentieren anmelden