AADSTS65001 🔷 Azure

AADSTS65001: The user or administrator has not consented to use the application

The app needs permissions that haven’t been granted for this user or tenant.

Seen on: Azure

Meaning

Delegated permissions need user or admin consent; many Microsoft Graph permissions need admin consent. Non-interactive flows (client credentials, on-behalf-of, ROPC) can’t show a consent prompt, so they fail with 65001.

Common causes

  • Required permission not consented
  • Admin consent required but only user consent attempted
  • User consent disabled by tenant policy
  • New permission added to the app without re-consent

⚡ Quick fix

  1. Grant admin consent in App registrations → API permissions
  2. Trigger interactive consent with prompt=consent
  3. Ask an admin to approve via the admin consent URL

Detailed fix by platform

Azure CLI

  1. az ad app permission admin-consent --id <app-id>

How to diagnose

  1. Permissions — API permissions list and status
  2. Policy — User consent settings
  3. Flow — Interactive or not?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.