logo
search
Permission & Access Issues

How to Fix SharePoint 401 Unauthorized with App-Only Authentication

Khadija KhanKhadija Khan Oct 1, 2026 868 views

Question details

The user needs to resolve a 401 Unauthorized error occurring in a C# SharePoint application after switching to app-only authentication.

How to Fix SharePoint 401 Unauthorized with App-Only Authentication
Product
Microsoft SharePoint
Device & OS
not provided
Scenario
Developing a C# application using SharePoint APIs and transitioning from delegated authentication to app-only authentication.
Observed behavior
The application successfully issues an access token, but subsequent API calls to SharePoint return a 401 Unauthorized error.
Before you start

Ensure you have Azure Active Directory (Entra ID) Administrator privileges to review, modify, and grant tenant-wide admin consent for application permissions.

Solution 1Recommended

Verify Application Permissions and Admin Consent

Ensure your Azure AD application is configured with 'Application' permissions (not Delegated) and that tenant-wide admin consent has been successfully granted.

When switching to app-only authentication, the context changes entirely. The application no longer acts on behalf of a user, meaning it relies strictly on the Application permissions granted in Azure AD. Without admin consent, the token generated will lack the necessary roles, leading to a 401 Unauthorized response from SharePoint.

1
Access App Registrations

Sign in to the Azure portal and navigate to Microsoft Entra ID (formerly Azure Active Directory), then select 'App registrations' and click on your application.

2
Modify API Permissions

Navigate to the 'API permissions' blade. Click 'Add a permission', select SharePoint (or Microsoft Graph, depending on your endpoint), and choose 'Application permissions'.

3
Select Required Roles

Select the necessary permissions required for your app's operation (e.g., Sites.Read.All, Sites.Manage.All) and click 'Add permissions'.

4
Grant Admin Consent

Click the 'Grant admin consent for [Your Tenant]' button next to the permission list and confirm the prompt to apply the changes tenant-wide.

Verify Application Permissions and Admin Consent
Propagation Delay: After granting admin consent, it may take a few minutes for the permissions to fully propagate across the Microsoft 365 environment. Wait a few moments before requesting a new token.
Free Microsoft Office alternative

Boost Your Development Workflow with WPS Office

While troubleshooting complex API integrations like SharePoint authentication, a lightweight and reliable office suite is essential for documenting code, tracking API specifications, and managing project plans. WPS Office provides a seamless, free alternative to Microsoft Office.

  1. 1. Visit the WPS Website: Go to the official WPS Office website using your web browser.
  2. 2. Download the Installer: Click the 'Free Download' button to get the latest version for your operating system.
  3. 3. Install and Launch: Run the downloaded installer and follow the quick setup instructions to start using your new office suite.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight installation with fast startup times, ideal for a developer's demanding system.Built-in PDF editor and tabbed document interface to manage technical specs efficiently.Cross-platform support across Windows, macOS, Linux, and mobile devices.
microsoft office alternative - wps office

Frequently Asked Questions

Why do I get a 401 Unauthorized error only with app-only authentication?

Delegated authentication uses the permissions of the logged-in user, whereas app-only authentication relies entirely on Application permissions granted by an administrator. If the app permissions are missing, incorrect, or lack admin consent, SharePoint will reject the request with a 401 error.

Can I use client secrets for SharePoint app-only authentication in modern apps?

For Microsoft Graph APIs interacting with SharePoint, client secrets are generally supported. However, if you are connecting directly to SharePoint REST APIs or using CSOM via Azure AD app-only access, certificate-based authentication is strongly recommended and often required.

How can I check if my tenant allows custom app authentication for SharePoint?

Newer Microsoft 365 tenants disable ACS-based custom app authentication by default. If you are using ACS, you must enable it via the SharePoint Online Management Shell using the command: 'Set-SPOTenant -DisableCustomAppAuthentication $false'. However, migrating to Azure AD applications with certificates is the recommended modern approach.