logo
search
Others

How to Fix Microsoft Cloud App Security API Returning HTML 500 Errors

Ayan MasoodAyan Masood Sep 25, 2026 869 views

Question details

The user is receiving an HTML page with an HTTP 500 error code instead of a JSON response when making requests to the Microsoft Cloud App Security discovered-app stream API endpoints.

Troubleshooting Microsoft Cloud App Security API HTML 500 Errors
Product
Microsoft Cloud App Security
Device & OS
not provided
Scenario
Querying discovered-app stream endpoints via API requests to retrieve security data in JSON format.
Observed behavior
The API endpoint unexpectedly returns an HTTP 500 Internal Server Error formatted as an HTML page, while other endpoints function normally or return the expected HTTP 404 errors.
Before you start

Verify that your API request headers, authentication tokens, and request body are formatted exactly as specified in the latest Microsoft Cloud App Security documentation before reporting a backend server issue.

Solution 1Recommended

Post the Issue to Microsoft Q&A Developer Support

Since an HTTP 500 error indicates an internal server issue with the API endpoint itself, contacting Microsoft's developer specialists is the necessary course of action.

An HTTP 500 Internal Server Error typically implies a failure on the server side rather than a client-side misconfiguration. Because the Microsoft Cloud App Security API is a specialized enterprise service, its backend availability, authentication mechanisms, and endpoint behaviors must be investigated by Microsoft engineers.

The most effective way to reach the right specialists for API and development-related queries is through the Microsoft Q&A platform.

1
Navigate to Microsoft Q&A

Open your web browser and go to the official Microsoft Q&A forum at https://learn.microsoft.com/en-us/answers/questions/.

2
Draft Your Question

Click the 'Ask a question' button and write a clear title describing the HTML 500 error on the discovered-app stream endpoints.

3
Provide Necessary Context

In the body of your post, include the exact request URL, the HTTP 500 response status, your authentication method (e.g., Bearer token), and the relevant API permissions assigned.

4
Sanitize Your Data

Before publishing, ensure you completely remove any API secrets, passwords, authentication tokens, or sensitive tenant IDs to maintain your organization's security.

Post the Issue to Microsoft Q&A Developer Support
Why does the API return HTML instead of JSON?: When a web server or proxy encounters a fatal application error, it may fall back to a default HTML error page generated by the web server (like IIS) rather than passing the error through the application's JSON formatter.
Free Microsoft Office alternative

Simplify Your Workflow with WPS Office

While troubleshooting complex enterprise API server errors requires specialized backend support, your daily document management shouldn't be complicated. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office, letting you create and edit documents, spreadsheets, and presentations with ease.

  1. 1. Visit the official website: Go to the official WPS Office website to download the latest version.
  2. 2. Install the suite: Run the lightweight installer and follow the quick on-screen instructions.
  3. 3. Start working seamlessly: Open your existing Word, Excel, or PowerPoint files without worrying about formatting issues.
Fully compatible with Microsoft Office formats (.docx, .xlsx, .pptx).Lightweight installation ensures fast startup and smooth operation on any PC.Familiar ribbon interface guarantees a seamless, zero-learning-curve migration.All-in-one suite includes a built-in PDF editor for streamlined document handling.
microsoft office alternative - wps office

Frequently Asked Questions

What does an HTTP 500 error mean when calling a REST API?

An HTTP 500 Internal Server Error is a generic error message indicating that the server encountered an unexpected condition that prevented it from fulfilling the client's API request. It typically points to a backend code exception or infrastructure issue rather than a client-side problem.

Can incorrect API authentication cause a 500 error?

Normally, authentication issues return an HTTP 401 (Unauthorized) or 403 (Forbidden). However, if the API's authentication validation logic crashes or encounters an unhandled exception during token verification, it might unexpectedly result in a 500 error.

Is the discovered-app stream endpoint deprecated?

API endpoints can change or be deprecated as Microsoft updates Defender for Cloud Apps. Always refer to the latest official Microsoft Learn API documentation for Cloud App Security to verify if an endpoint has been replaced by a newer version.