How to Fix HTTP 401 Errors When Connecting Azure App Service to SharePoint 2019
Question details
The user needs to resolve HTTP 401 authentication errors when attempting to connect an Azure App Service to an on-premises SharePoint Server 2019 utilizing Hybrid Connections.

- Product
- Azure App Service and SharePoint Server 2019
- Device & OS
- not provided
- Scenario
- Connecting an Azure App Service to on-premises SharePoint Server 2019 through Hybrid Connections using authentication tokens.
- Observed behavior
- The connection fails, returning HTTP 401 (Unauthorized) errors because username-and-password authentication or Azure AD access tokens are used without a compatible trust configuration.
Ensure you have administrative access to both the Azure App Service environment and the on-premises SharePoint Server 2019 farm, and have an appropriate X.509 certificate ready for configuration.
Configure High-Trust Server-to-Server Authentication
Set up an X.509 certificate to establish a high-trust relationship between your Azure App Service and on-premises SharePoint 2019 farm.
SharePoint Server 2019 cannot typically validate Azure AD tokens directly without appropriate integration. Bypassing HTTP 401 errors over Hybrid Connections requires implementing a high-trust authentication model using an X.509 certificate and Bearer tokens.
Ensure the App Management Service and Microsoft SharePoint Foundation Subscription Settings Service are properly configured and running on your SharePoint Server 2019 farm.
Use SharePoint Management Shell to configure your X.509 certificate as a trusted security-token issuer on the SharePoint 2019 server.
Register the application principal and grant it the required permissions within SharePoint to allow access from the Azure App Service.
Update the Azure App Service application code to generate certificate-signed JSON Web Tokens (JWTs) using the private key of your X.509 certificate.
Ensure your Azure App Service sends the generated JWTs as Bearer tokens in the HTTP Authorization header when making requests to the on-premises SharePoint APIs.

Looking for a Lightweight Alternative to Manage Your Documents?
While configuring complex SharePoint and Azure server environments, managing your daily document workloads shouldn't be a hassle. WPS Office offers a free, lightweight, and highly compatible alternative to Microsoft Office for creating and editing your team's documents seamlessly.

Frequently Asked Questions
Can I use Azure AD tokens directly with SharePoint 2019 on-premises?
Generally, SharePoint Server 2019 cannot validate Azure AD access tokens directly without a highly configured integration environment. It is recommended to use high-trust server-to-server authentication relying on an X.509 certificate instead.
Why am I getting an HTTP 401 error over an Azure Hybrid Connection?
This error typically occurs when the Azure App Service attempts to use standard username-and-password authentication or invalid Azure AD tokens against your on-premises SharePoint, rather than utilizing a properly configured high-trust security token.
What is a high-trust SharePoint add-in?
A high-trust add-in is a specifically configured application on a SharePoint on-premises environment that relies on digital certificates to establish a trust relationship. It allows the external application to authenticate securely via server-to-server communication using JWT Bearer tokens.




