Summary
I cannot grant admin consent to Microsoft Graph application permissions for an App Registration in our new tenant. There is an orphan "Microsoft Internal" Service Principal with appId ending in 0000 and displayName "Microsoft Graph" that appears to be blocking the provisioning of the correct Microsoft Graph SP.
Context
ItemValueTenant[redacted]TenantId[redacted]SubscriptionId[redacted]LicenseO365_BUSINESS_ESSENTIALS## Affected App Registration
- Name:
Azhum Platform
- AppId (ClientId):
[redacted]
- ObjectId:
[redacted]
- Service Principal ObjectId:
[redacted]
Orphan SP blocking provisioning
FieldValueId[redacted]AppId00000003-0000-0000-c000-000000000000DisplayNameMicrosoft GraphServicePrincipalTypeApplicationFlag"Microsoft Internal" (cannot be deleted or renamed)## Required permissions we cannot consent to
-
User.ReadWrite.All (Application)
-
AppRoleAssignment.ReadWrite.All (Application)
-
Directory.Read.All (Application)
Errors observed (in order of attempts)
Dynamic scope is invalid: application 00000003-0000-0000-c000-000000000046 does not exist
2. az ad app permission admin-consent
Bad Request (Request_BadRequest): The application needs access to a service that your organization has not subscribed to. Please contact your administrator to review the configuration of your service subscriptions.
3. Browser /adminconsent URL flow
AADSTS650054: The application asked for permissions to access a resource that has been removed or no longer available in the tenant.
4. POST to Microsoft Graph REST
POST https://graph.microsoft.com/v1.0/servicePrincipals
Content-Type: application/json
{"appId":"00000003-0000-0000-c000-000000000046"}
Response:
{
"error": {
"code": "Request_BadRequest",
"message": "Property displayName is invalid.",
"details": [{
"code": "GenericError",
"message": "Property displayName is invalid.",
"target": "displayName"
}]
}
}
5. POST with custom displayName
Creates a service principal with:
-
servicePrincipalType: Legacy
-
appOwnerOrganizationId: null
-
appRoles: []
The orphan SP gets auto-deleted by the backend within minutes.
6. Cloud Shell az ad ...
Audience xxxxxxxxxxxxxxx is not a supported MSI token audience.
7. az ad sp delete
Specified App Principal ID is Microsoft Internal.
What I have tried
- Deleted the orphan SP from
directory/deletedItems and confirmed deletedItems is empty
- Created a new SP via REST using only the
appId
- Created SP with custom displayName
- Verified tenant license is active
- Verified
Get-MgServicePrincipal only returns the orphan SP and related Graph applications, but not the expected Microsoft Graph SP
Request
Please clean up the orphan Microsoft Internal service principal from this tenant so the correct Microsoft Graph Service Principal can be provisioned and admin consent can be granted successfully.
This issue is blocking Microsoft Graph-based identity management operations in our SaaS platform.