How to Fix Microsoft Cloud App Security API Returning HTML 500 Errors
Question details
The user is receiving an HTML page with an HTTP 500 error code instead of a JSON response when making requests to the Microsoft Cloud App Security discovered-app stream API endpoints.

- Product
- Microsoft Cloud App Security
- Device & OS
- not provided
- Scenario
- Querying discovered-app stream endpoints via API requests to retrieve security data in JSON format.
- Observed behavior
- The API endpoint unexpectedly returns an HTTP 500 Internal Server Error formatted as an HTML page, while other endpoints function normally or return the expected HTTP 404 errors.
Verify that your API request headers, authentication tokens, and request body are formatted exactly as specified in the latest Microsoft Cloud App Security documentation before reporting a backend server issue.
Post the Issue to Microsoft Q&A Developer Support
Since an HTTP 500 error indicates an internal server issue with the API endpoint itself, contacting Microsoft's developer specialists is the necessary course of action.
An HTTP 500 Internal Server Error typically implies a failure on the server side rather than a client-side misconfiguration. Because the Microsoft Cloud App Security API is a specialized enterprise service, its backend availability, authentication mechanisms, and endpoint behaviors must be investigated by Microsoft engineers.
The most effective way to reach the right specialists for API and development-related queries is through the Microsoft Q&A platform.
Open your web browser and go to the official Microsoft Q&A forum at https://learn.microsoft.com/en-us/answers/questions/.
Click the 'Ask a question' button and write a clear title describing the HTML 500 error on the discovered-app stream endpoints.
In the body of your post, include the exact request URL, the HTTP 500 response status, your authentication method (e.g., Bearer token), and the relevant API permissions assigned.
Before publishing, ensure you completely remove any API secrets, passwords, authentication tokens, or sensitive tenant IDs to maintain your organization's security.

Simplify Your Workflow with WPS Office
While troubleshooting complex enterprise API server errors requires specialized backend support, your daily document management shouldn't be complicated. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office, letting you create and edit documents, spreadsheets, and presentations with ease.
- 1. Visit the official website: Go to the official WPS Office website to download the latest version.
- 2. Install the suite: Run the lightweight installer and follow the quick on-screen instructions.
- 3. Start working seamlessly: Open your existing Word, Excel, or PowerPoint files without worrying about formatting issues.

Frequently Asked Questions
What does an HTTP 500 error mean when calling a REST API?
An HTTP 500 Internal Server Error is a generic error message indicating that the server encountered an unexpected condition that prevented it from fulfilling the client's API request. It typically points to a backend code exception or infrastructure issue rather than a client-side problem.
Can incorrect API authentication cause a 500 error?
Normally, authentication issues return an HTTP 401 (Unauthorized) or 403 (Forbidden). However, if the API's authentication validation logic crashes or encounters an unhandled exception during token verification, it might unexpectedly result in a 500 error.
Is the discovered-app stream endpoint deprecated?
API endpoints can change or be deprecated as Microsoft updates Defender for Cloud Apps. Always refer to the latest official Microsoft Learn API documentation for Cloud App Security to verify if an endpoint has been replaced by a newer version.




