How to set up a multi tenant application so my users can authorize Azure DevOps apis to be called

Sophie Higgins 0 Reputation points

I've set up an application in Microsoft Entra Id following this documentation:
I've then made changes to make it multi tenant following this: 

I've granted the following API permissionsScreenshot 2024-07-02 at 15.28.16

And I'm passing the scope into the authorize url scope parameter like so:

When I try to use any user/organisation account to sign up there's always an error saying that the scope does not exist e.g. error=invalid_scope&

I get the same error if I pass in completely invalid scope values. So I suspect I'm doing something wrong in the set-up of permissions in entra or the format of the parameter.

Anyone know what's going wrong?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,351 questions
{count} votes