How to Fix SharePoint 401 Unauthorized with App-Only Authentication
Question details
The user needs to resolve a 401 Unauthorized error occurring in a C# SharePoint application after switching to app-only authentication.

- Product
- Microsoft SharePoint
- Device & OS
- not provided
- Scenario
- Developing a C# application using SharePoint APIs and transitioning from delegated authentication to app-only authentication.
- Observed behavior
- The application successfully issues an access token, but subsequent API calls to SharePoint return a 401 Unauthorized error.
Ensure you have Azure Active Directory (Entra ID) Administrator privileges to review, modify, and grant tenant-wide admin consent for application permissions.
Verify Application Permissions and Admin Consent
Ensure your Azure AD application is configured with 'Application' permissions (not Delegated) and that tenant-wide admin consent has been successfully granted.
When switching to app-only authentication, the context changes entirely. The application no longer acts on behalf of a user, meaning it relies strictly on the Application permissions granted in Azure AD. Without admin consent, the token generated will lack the necessary roles, leading to a 401 Unauthorized response from SharePoint.
Sign in to the Azure portal and navigate to Microsoft Entra ID (formerly Azure Active Directory), then select 'App registrations' and click on your application.
Navigate to the 'API permissions' blade. Click 'Add a permission', select SharePoint (or Microsoft Graph, depending on your endpoint), and choose 'Application permissions'.
Select the necessary permissions required for your app's operation (e.g., Sites.Read.All, Sites.Manage.All) and click 'Add permissions'.
Click the 'Grant admin consent for [Your Tenant]' button next to the permission list and confirm the prompt to apply the changes tenant-wide.

Check Token Audience and Application Roles
Validate that the generated access token contains the correct audience (aud) claim and the expected application roles.
Boost Your Development Workflow with WPS Office
While troubleshooting complex API integrations like SharePoint authentication, a lightweight and reliable office suite is essential for documenting code, tracking API specifications, and managing project plans. WPS Office provides a seamless, free alternative to Microsoft Office.
- 1. Visit the WPS Website: Go to the official WPS Office website using your web browser.
- 2. Download the Installer: Click the 'Free Download' button to get the latest version for your operating system.
- 3. Install and Launch: Run the downloaded installer and follow the quick setup instructions to start using your new office suite.

Frequently Asked Questions
Why do I get a 401 Unauthorized error only with app-only authentication?
Delegated authentication uses the permissions of the logged-in user, whereas app-only authentication relies entirely on Application permissions granted by an administrator. If the app permissions are missing, incorrect, or lack admin consent, SharePoint will reject the request with a 401 error.
Can I use client secrets for SharePoint app-only authentication in modern apps?
For Microsoft Graph APIs interacting with SharePoint, client secrets are generally supported. However, if you are connecting directly to SharePoint REST APIs or using CSOM via Azure AD app-only access, certificate-based authentication is strongly recommended and often required.
How can I check if my tenant allows custom app authentication for SharePoint?
Newer Microsoft 365 tenants disable ACS-based custom app authentication by default. If you are using ACS, you must enable it via the SharePoint Online Management Shell using the command: 'Set-SPOTenant -DisableCustomAppAuthentication $false'. However, migrating to Azure AD applications with certificates is the recommended modern approach.




