Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error Authorization_RequestDenied

Authorization_RequestDenied: the admin centre refuses your change

11 min read Updated October 5, 2026 Microsoft 365 & Entra ID

Fix it now

Authorization_RequestDenied is “Insufficient privileges to complete the operation”. Entra ID accepted who you are and refused what you asked to do: the signed-in account lacks the directory role, or the app registration lacks the Microsoft Graph permission, that the operation requires.

PowerShell with the Microsoft Graph module. Read the scopes before and after

Get-MgContext
Connect-MgGraph -Scopes "User.ReadWrite.All"
Get-MgContext | Select -ExpandProperty Scopes
  1. Read the Scopes line from Get-MgContext. It shows the permissions the session actually holds, not the ones you asked for.
  2. In the Entra admin centre open Roles and administrators, find the role you believe you have, open Assignments and confirm your account is genuinely listed.
  3. If you use Privileged Identity Management, activate the role. An eligible assignment grants nothing until it is activated.
  4. For an app-only script, check App registrations, API permissions: the matching application permission must be there and must have admin consent granted.
  5. Sign out and back in after any role change so a fresh token carries the new claims.

Being a Global Administrator in one portal does not carry into every Graph operation. The token has to carry the scope.

If the operation now succeeds you can stop here. If not, the next section covers the three other codes that arrive at the same screen from somewhere else.

Why it happens

Two separate things have to line up before Graph will do what you asked, and this error means one of them did not. The first is the directory role held by the principal making the call – a person, or the service principal behind an app registration. The second is the permission on the token itself: a delegated scope for a signed-in user, or an application permission with admin consent for app-only calls. A correct role with the wrong scope fails, and so does the reverse.

Microsoft’s troubleshooting for this code works through exactly those two: assign an appropriate Microsoft Entra RBAC role to the app registration – it uses User Administrator as the example for managing users – and add the required API permissions, then grant admin consent. It also names the least-privileged pairing for a specific job, which is a good model for the rest: to change the accountEnabled property on administrator accounts you need Privileged Authentication Administrator, and the permissions User.EnableDisableAccount.All together with User.Read.All.

The other three codes in this article are not permission failures at all, and it is worth being honest about how thinly they are documented. Request_BadRequest appears in Microsoft’s guidance on group sensitivity labels, where it is returned because the directory settings already exist and creating a new property:value pair therefore fails – the remedy is to update the existing settings object rather than create another. Request_ResourceNotFound appears as the expected 404 when an application is not present in the tenant. Neither has a published general definition, so treat any confident universal meaning for them with caution.

Directory_QuotaExceeded is the one with a real number behind it. A non-administrator may create no more than 250 Microsoft Entra resources – applications and service principals – and both active resources and soft-deleted ones that are still available to restore count towards that limit. Deleting an application does not free the quota; permanently deleting it from the deleted items container does. Soft-deleted objects remain restorable for up to 30 days.

The account does not hold the role it thinks it does

You have this one if Authorization_RequestDenied for a person, on an operation that colleagues can perform.

  1. Open Roles and administrators in the Entra admin centre, open the role, and check Assignments for your account by name.
  2. Assign the least-privileged role that covers the operation rather than reaching for Global Administrator.
  3. Sign out and back in, so the next token carries the new role.

Microsoft’s own example for user management is User Administrator. Start from the least-privileged role that does the job and move up only if it genuinely does not.

An eligible PIM role has not been activated

You have this one if The role appears against your account, the operation still fails, and the assignment type is Eligible rather than Active.

  1. Activate the role in Privileged Identity Management before running the operation.
  2. Confirm the activation completed – approval workflows can hold it.
  3. Obtain a fresh token afterwards; an existing session does not gain the role retrospectively.

The session holds the wrong scopes

You have this one if A script fails while the same person succeeds in the portal.

  1. Run Get-MgContext and read the Scopes line.
  2. Reconnect with the scope the operation needs, for example Connect-MgGraph -Scopes "User.ReadWrite.All", and consent when prompted.
  3. Prefer the narrowest scope that works over a broad one that happens to be familiar.

An app-only call has no consented application permission

You have this one if A daemon or automation account fails consistently, with no user involved.

  1. Open App registrations, select the application, then API permissions.
  2. Add the required application permission – not the delegated one – and grant admin consent.
  3. Assign the app registration’s service principal an appropriate directory role where the operation needs one as well as a permission.

Application permissions and delegated permissions are separate lists. Adding the delegated version of a permission does nothing for an app-only call.

A non-admin has hit the object creation quota

You have this one if Directory_QuotaExceeded, from a developer or automation account that creates app registrations.

  1. Permanently delete unneeded applications and service principals from the deleted items container – soft-deleted objects still count.
  2. Check whether an automation is creating registrations it never cleans up.
  3. Have an administrator create the objects instead, or raise the account’s role if that is appropriate.

Full reference

Role, permission, or neither

Code What it is First thing to check
Authorization_RequestDenied Insufficient privileges to complete the operation The directory role, then the Graph permission on the token
Request_BadRequest The request itself is invalid for that operation Whether the object or setting you are creating already exists
Request_ResourceNotFound The referenced object was not found Whether it exists in this tenant at all, and whether you are in the right tenant
Directory_QuotaExceeded An object creation quota has been reached Soft-deleted applications and service principals still counting against 250

A worked least-privilege example

Microsoft’s own example on this error is useful because it shows both halves at once. To enable or disable a user account through Graph you need the permission User.EnableDisableAccount.All in combination with User.Read.All. To do the same thing to an administrator’s account you additionally need the Privileged Authentication Administrator role, because changing an administrator’s sign-in state is a privileged operation regardless of which permission the token carries.

Reading a Graph error properly

  • The code field is the machine-readable name – Authorization_RequestDenied – and the message field is the human sentence. Quote the code, not the sentence, when searching.
  • The innererror object often carries a request-id and a date. Keep both: they are what support asks for.
  • An HTTP 403 with this code is a privileges problem. An HTTP 403 with a different code may not be.
  • A 404 is not always absence. Graph returns Request_ResourceNotFound when an object exists but the caller cannot see it, which looks identical from the client.

Object quotas worth knowing

Limit Value Counts what
Non-admin resource creation 250 Applications and service principals created by that user
Soft-deleted objects Still counted Restorable for up to 30 days, then permanently deleted

The soft-delete detail is the part that surprises people. A developer who has tidied up conscientiously by deleting their old app registrations is still at the quota, because deleted-but-restorable objects continue to count. Permanent deletion from the deleted items container is what actually frees the allowance.

When the role and the scope both look right

  • Confirm you are operating against the tenant you think you are. A token for the wrong tenant produces confident-looking failures.
  • Check whether the target object is itself protected. Operations against administrators, and against role-assignable groups, need higher privilege than the same operation against ordinary objects.
  • Look for Conditional Access on the sign-in that issued the token; a policy can restrict what the session is allowed to do.
  • Re-authenticate. A token issued before a role change does not gain the role, and sessions can be long-lived.
  • For app-only calls, confirm admin consent was granted for the tenant rather than merely requested.

When a licence is the actual fix

Nothing here requires a purchase. Directory roles are part of the service, assigning the correct least-privileged role costs nothing, and consenting a Graph permission costs nothing either – so if the answer to your ticket is “give this account User Administrator”, stop reading. Where a licence becomes relevant is how those roles are granted rather than whether they can be. Privileged Identity Management, which gives you eligible rather than standing assignments, time-limited activation, approval workflows and an audit trail of every elevation, is a Microsoft Entra ID P2 feature. If your standing answer to this error is to leave people permanently in high-privilege roles, P2 is the supported way to stop doing that. Arco can supply Entra ID P2 for the administrators who need it, and will first confirm whether the suite you already own includes it.

Every code this article covers

Code What it points at Source
Authorization_RequestDenied “Insufficient privileges to complete the operation” – the caller lacks the Microsoft Entra role, or the Microsoft Graph permission, that the operation requires Microsoft Learn
Request_BadRequest The request is invalid for that operation. Microsoft documents it in one narrow scenario – directory settings that already exist, so creating a new property:value pair fails – rather than as a general code Microsoft Learn
Request_ResourceNotFound The referenced object was not found. Microsoft documents it as the expected 404 body when an application is not present in the tenant; it can also mean the caller cannot see the object Microsoft Learn
Directory_QuotaExceeded A non-administrator has reached the limit of 250 Microsoft Entra resources they may create. Soft-deleted applications and service principals still count until they are permanently deleted Microsoft Learn

Confirm the fix worked

  1. Get-MgContext shows the scope the operation needs in its Scopes list.
  2. Roles and administrators shows your account under Assignments for the role you expect, as an active rather than eligible assignment.
  3. For an app-only call, API permissions shows the application permission with admin consent granted.
  4. The operation completes and returns the object rather than a 403.
  5. The role you used is the least-privileged one that works, not Global Administrator by default.

Questions people ask about this

I am a Global Administrator. Why am I still refused?

Because the token has to carry the permission as well as the account holding the role. A PowerShell session connected without the required scope is refused regardless of your directory role. Read the Scopes line from Get-MgContext and reconnect with what the operation needs.

Does this cost anything to fix?

No. Assigning the right role and consenting the right permission are both part of the service. A licence only enters the picture if you want Privileged Identity Management, which is an Entra ID P2 feature, to grant those roles just in time rather than permanently.

Why did Directory_QuotaExceeded appear after I deleted a load of app registrations?

Because soft-deleted applications and service principals still count towards the 250-resource limit for a non-admin. They stay restorable for up to 30 days. Permanently delete them from the deleted items container to free the quota.

Is Request_ResourceNotFound always a missing object?

No. Graph returns it when the object does not exist and also when the caller cannot see it, which look the same from the client. Confirm you are in the right tenant and that the caller has read access before concluding the object is gone.

What role should I use for user management?

Microsoft’s own example is User Administrator. For changing the sign-in state of administrator accounts specifically, it names Privileged Authentication Administrator as the least-privileged role, with the permissions User.EnableDisableAccount.All and User.Read.All.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error AADSTS70008 and AADSTS700082: the refresh token expired or was revoked Free Fix Teams CAA20003 and CAA2000C: clock skew, Conditional Access and forced prompts License Error MutuallyExclusiveViolation and DependencyViolation in group licence assignment Free Fix AADSTS7000215 and AADSTS700016: bad client secret or missing app registration
โ† Back to Knowledge Base