I am getting this error when trying to log in using a custom IEF policy with a local account. I have verified that my IEFProxy is set up to access IEFApp and granted consent and that their reply urls are correct. What am missing?
I have faced the same problem while configuring Identity Experience Framework for Azure Active Directory B2C.
The problem was that I missed the step of granting consent on behalf of all users in the tenant (only the global admin can). For doing that in the legacy flow just go in
Azure Active Directory > App Registration (Legacy) > ProxyIdentityExperienceFramework > Settings > Required Permissions
and click on "Grant Permissions"
In the new flow its:
Azure Active Directory > App Registration > ProxyIdentityExperienceFramework (it's in the 'All applications' tab) > API permissions
and click on "Grant admin consent for ...".
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With