AADSTS65001: The user or administrator has not consented to use the application
The app needs permissions that haven’t been granted for this user or tenant.
Seen on:
Azure
Meaning
Delegated permissions need user or admin consent; many Microsoft Graph permissions need admin consent. Non-interactive flows (client credentials, on-behalf-of, ROPC) can’t show a consent prompt, so they fail with 65001.
Common causes
- Required permission not consented
- Admin consent required but only user consent attempted
- User consent disabled by tenant policy
- New permission added to the app without re-consent
⚡ Quick fix
- Grant admin consent in App registrations → API permissions
- Trigger interactive consent with prompt=consent
- Ask an admin to approve via the admin consent URL
Detailed fix by platform
Azure CLI
az ad app permission admin-consent --id <app-id>
How to diagnose
- Permissions — API permissions list and status
- Policy — User consent settings
- Flow — Interactive or not?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Azure
- AADSTS50076 Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
- AuthorizationPermissionMismatch Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission
- AADSTS700016 Azure AD (Entra ID): AADSTS700016 Application not found in the directory
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026