Symptom
When connecting Microsoft Advertising to Shirofune, the message "The authentication process failed" may appear after signing in, and the connection cannot be completed.
This article covers cases where the details of AADSTS650052 indicate that the service principal for Microsoft Advertising API Service is missing, as shown below. The error code may appear on screen, while the detailed error text is included in the URL in your browser’s address bar.
AADSTS650052: The app is trying to access a service 'Microsoft Advertising API Service' that your organization lacks a service principal for.
If the error code is AADSTS65004, see If AADSTS65004 appears.
Cause
A common cause is that the Microsoft Entra ID (formerly Azure AD) tenant of the signing-in account does not have a service principal for "Microsoft Advertising API Service". A service principal represents the service within your organization’s tenant. Creating it is separate from consenting to access permissions.
- These steps apply when the error described above occurs in your organization’s tenant while connecting with a work or school account.
- The missing service principal may be related to your organization’s application consent settings or its previous use of the Microsoft Advertising API.
- Your organization’s Microsoft Entra administrator must register the service in the target tenant and approve any required permissions.
Note: When the service principal is missing, the consent operation may also return the same error. Register the service in the tenant using Step 1, then grant admin consent in Step 2 if required.
Resolution steps
Steps 1 and 2 must be performed by your organization's Microsoft Entra administrator (Global Administrator, Application Administrator, or Cloud Application Administrator).
Step 1: Register the Microsoft Advertising service in the tenant
The administrator runs one of the following commands in the tenant of the work account being connected. Replace {TENANT_ID} with the target organization’s tenant ID, found under Microsoft Entra ID → Overview → Basic information. If you manage multiple organizations, confirm that you are connected to the correct tenant. This can also be done in Azure Cloud Shell, which you can launch from the >_ icon in the top bar of the Azure portal (no local installation required).
Using Microsoft Graph PowerShell:
Connect-MgGraph -TenantId "{TENANT_ID}" -Scopes "Application.ReadWrite.All"
New-MgServicePrincipal -AppId "d42ffc93-c136-491d-b4fd-6f18168c68fd"Using Azure CLI:
az login --tenant "{TENANT_ID}" --allow-no-subscriptions
az ad sp create --id d42ffc93-c136-491d-b4fd-6f18168c68fdNote: These steps follow Microsoft’s documentation to register the existing Microsoft Advertising API Service in the target tenant. Do not create a new app with the same name. If you receive an error indicating that it already exists, verify the application ID in Step 3 and proceed to Step 2 if required.
Step 2: Approve the Shirofune app if required (admin consent)
After completing Step 1, if admin consent for Shirofune is required, the administrator opens the following URL in a browser. Replace {TENANT_ID} with your organization's tenant ID (you can find it in Microsoft Entra ID → Overview → Basic information → Tenant ID).
https://login.microsoftonline.com/{TENANT_ID}/adminconsent?client_id=9f44340e-8212-43b5-b53b-9528cd99853dIn the "Permissions requested" dialog, review the organization, application name, and requested permissions. Click Accept if they are appropriate.
Shirofune’s Microsoft Advertising connection uses Microsoft Advertising management (msads.manage / ads.manage) and offline access. The admin consent screen shows permissions based on the app registration settings. If anything is unclear, contact Shirofune Support before accepting. The Application.ReadWrite.All permission requested by PowerShell in Step 1 is for Microsoft Graph PowerShell to let the administrator create the service principal; it is separate from permissions granted to the Shirofune app.
About the screen after approval: An error page may appear at the redirect destination after approval. Do not judge the result solely by how the page looks. Check that the destination URL contains
admin_consent=Trueand noerrorparameter. If you cannot confirm this, or anerrorparameter is present, contact support with the information listed below.
Step 3: Confirm the service principal was created (optional)
In the Microsoft Entra admin center → Enterprise applications:
- Change the "Application type" filter to "All applications" (so that Microsoft applications are included).
- Search by name for
Microsoft Advertising API Serviceand verify that its application ID isd42ffc93-c136-491d-b4fd-6f18168c68fd. - If the matching application appears, the service principal exists. This does not confirm that admin consent for Shirofune has been granted or that the user has access to the advertising account.
Step 4: Reconnect in Shirofune
Return to Shirofune and try connecting Microsoft Advertising again with the work account you are currently using. If the same error persists or a different error appears, contact Shirofune Support with the displayed code.
If AADSTS65004 appears
AADSTS65004 means that consent to Shirofune was not given on the permissions screen shown after signing in to Microsoft. It is not a system malfunction. Take the following action depending on the screen you saw.
If you selected "Cancel" on the permissions screen
Connect Microsoft Advertising in Shirofune again, and click Accept on the permissions screen.
If "Need admin approval" was displayed
Your organization’s settings do not allow users to consent to apps themselves. In this case, retrying will not complete the connection. Ask your organization’s Microsoft Entra administrator to perform Step 2 (admin consent) above. After admin consent is granted, try connecting again in Shirofune.
Note: If
AADSTS650052appears during admin consent, start from Step 1.
Frequently asked questions
Q. The connection used to work, but this error suddenly started appearing.
The previous connection may have been made with a personal Microsoft account. A change of work account or tenant may also be involved. Check the error details. If they match the case covered by this article, ask your administrator to verify the service registration in the target tenant.
Q. I opened the approval link (the URL in Step 2) first, and got the same error.
When the service principal is missing, approval may return the same error. Register it in the target tenant using Step 1, then retry admin consent if required.
Q. I tried to add it via "+ New application" in the Microsoft Entra admin center, but could not find it.
Register the Microsoft Advertising API Service covered by this article in the target tenant using the commands in Step 1. Use the specified application ID to avoid creating a different app with the same name.
If the steps above do not resolve the issue
Please contact Shirofune support with the following information.
- If Step 1 failed: the output message of the command
- If an error appeared on the consent screen in Step 2: a screenshot of the screen including the error code
- If Step 2 ended on an error-looking page: the full URL from your browser's address bar (the result of the approval is recorded there)
Comments
0 comments
Article is closed for comments.