Service Azure qui fournit une plateforme de gestion hybride multicloud pour les API.
Microsoft Entra / Microsoft Graph: AADSTS70000 invalid_grant when exchanging authorization_code for MSA (hotmail) account - same flow works for other accounts
I have a .NET 8 backend app using the OAuth2 authorization_code flow to access Microsoft Graph. The authorization code is generated for the user via a consent page on login.live.com, then stored and exchanged by my app at https://login.microsoftonline.com/common/oauth2/v2.0/token.
The problem: For one specific hotmail.com account, the very first exchange attempt fails with this error:
{"error":"invalid_grant","error_description":"AADSTS70000: The request was denied because one or more scopes requested are unauthorized or expired. The user must first sign in and grant the client application access to the requested scope. Trace ID: 1a4ebf72-51d9-464e-87f4-91bac4142400 Correlation ID: 4b446ae8-31fe-4386-8368-389191c682d1 Timestamp: 2026-07-01 12:22:16Z","error_codes":[70000]}
What I've already verified:
- The app (client_id
b7b7f973-5e9e-4da9-b92c-d282abebbd0e) appears underaccount.live.com/consent/Managefor this account, with consent showing as granted. - I created a brand new hotmail account and tested the exact same flow — it works perfectly.
- Organizational Azure AD accounts also work fine with this same app and code path.
- Only this one specific account is affected.
My question: Can you check via the trace_id / correlation_id above why this specific exchange was rejected as "scopes unauthorized" despite consent appearing as granted? Could there be a delay or caching issue between the user granting consent and the token endpoint recognizing it?