79630978

Date: 2025-05-20 18:28:53
Score: 2
Natty:
Report link

Password grant requires client_id and client_secret. Try below parameters.

curl --location \
  --request POST \
  'https://login.microsoftonline.com/{tenantId}/oauth2/v2.0/token' \
  --header 'Content-Type: application/x-www-form-urlencoded' \
  --data-urlencode 'client_id={clientId}' \
  --data-urlencode 'client_secret={clientSecret}' \
  --data-urlencode 'username={username}' \
  --data-urlencode 'password={password}' \
  --data-urlencode 'scope=User.Read profile openid email' \
  --data-urlencode 'grant_type=password'

You may want to use any default scope like email incase it still doesn't work.

Reasons:
  • RegEx Blacklisted phrase (2): it still doesn't work
  • Long answer (-0.5):
  • Has code block (-0.5):
  • Low reputation (1):
Posted by: Jay Dudhatra