Cannot grant admin consent to Microsoft Graph permissions — orphan "Microsoft Internal" Service Principal blocking provisioning of correct Microsoft Graph SP in new tenant

Gerson Castillo 25 Puntos de reputación
2026-05-19T22:55:24.56+00:00

Summary

I cannot grant admin consent to Microsoft Graph application permissions for an App Registration in our new tenant. There is an orphan "Microsoft Internal" Service Principal with appId ending in 0000 and displayName "Microsoft Graph" that appears to be blocking the provisioning of the correct Microsoft Graph SP.

Context

ItemValueTenant[redacted]TenantId[redacted]SubscriptionId[redacted]LicenseO365_BUSINESS_ESSENTIALS## Affected App Registration

  • Name: Azhum Platform
  • AppId (ClientId): [redacted]
  • ObjectId: [redacted]
  • Service Principal ObjectId: [redacted]

Orphan SP blocking provisioning

FieldValueId[redacted]AppId00000003-0000-0000-c000-000000000000DisplayNameMicrosoft GraphServicePrincipalTypeApplicationFlag"Microsoft Internal" (cannot be deleted or renamed)## Required permissions we cannot consent to

  • User.ReadWrite.All (Application)
  • AppRoleAssignment.ReadWrite.All (Application)
  • Directory.Read.All (Application)

Errors observed (in order of attempts)

Dynamic scope is invalid: application 00000003-0000-0000-c000-000000000046 does not exist

Bad Request (Request_BadRequest): The application needs access to a service that your organization has not subscribed to. Please contact your administrator to review the configuration of your service subscriptions.

3. Browser /adminconsent URL flow

AADSTS650054: The application asked for permissions to access a resource that has been removed or no longer available in the tenant.

4. POST to Microsoft Graph REST

POST https://graph.microsoft.com/v1.0/servicePrincipals
Content-Type: application/json

{"appId":"00000003-0000-0000-c000-000000000046"}

Response:

{
  "error": {
    "code": "Request_BadRequest",
    "message": "Property displayName is invalid.",
    "details": [{
      "code": "GenericError",
      "message": "Property displayName is invalid.",
      "target": "displayName"
    }]
  }
}

5. POST with custom displayName

Creates a service principal with:

  • servicePrincipalType: Legacy
  • appOwnerOrganizationId: null
  • appRoles: []

The orphan SP gets auto-deleted by the backend within minutes.

6. Cloud Shell az ad ...

Audience xxxxxxxxxxxxxxx is not a supported MSI token audience.

7. az ad sp delete

Specified App Principal ID is Microsoft Internal.

What I have tried

  • Deleted the orphan SP from directory/deletedItems and confirmed deletedItems is empty
  • Created a new SP via REST using only the appId
  • Created SP with custom displayName
  • Verified tenant license is active
  • Verified Get-MgServicePrincipal only returns the orphan SP and related Graph applications, but not the expected Microsoft Graph SP

Request

Please clean up the orphan Microsoft Internal service principal from this tenant so the correct Microsoft Graph Service Principal can be provisioned and admin consent can be granted successfully.

This issue is blocking Microsoft Graph-based identity management operations in our SaaS platform.

Control de acceso basado en rol de Azure
Control de acceso basado en rol de Azure

Un servicio de Azure que proporciona administración de acceso específico para los recursos de Azure, lo que permite conceder a los usuarios solo los derechos necesarios para realizar sus trabajos.

0 comentarios No hay comentarios

Respuesta aceptada por el autor de la pregunta
Sridevi Machavarapu 33,820 Puntos de reputación Personal externo de Microsoft Moderador
2026-05-20T00:23:06.69+00:00

Hello Gerson Castillo,

As discussed offline, the issue was caused by invalid Microsoft Graph application permissions added using incorrect commands. Because of these invalid permission entries, admin consent could not be completed.

We reviewed the configuration together and removed the invalid API permissions from the App Registration.

To add the permissions correctly from the Azure Portal:

  • Go to Microsoft Entra ID > App registrations > Select the application
  • Open API permissions > Add a permission
  • Select Microsoft Graph > Application permissions
  • Add:
    • User.ReadWrite.All
    • AppRoleAssignment.ReadWrite.All
    • Directory.Read.All
  • Select "Add permissions" and then "Grant admin consent for <tenant>"
  • After re-adding the permissions through the portal, admin consent should work as expected.

No backend cleanup is required for the tenant.

¿Le resultó útil esta respuesta?

1 persona encontró esta respuesta útil.

0 respuestas adicionales

Ordenar por: Lo más útil

Su respuesta

Las respuestas pueden ser marcadas como Respuestas aceptadas por el autor de la pregunta, lo que indica a los usuarios que la respuesta resolvió su problema.