fix(client): use explicit Graph scopes for Teams Desktop NAA compatibility#616
Merged
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
This PR updates the @microsoft/teams.client authentication and Graph integration to improve Teams Desktop (Nested App Auth / OneAuth broker) compatibility by avoiding reliance on the Graph '.default' scope and by adjusting MSAL configuration/behavior for broker-specific errors.
Changes:
- Update MSAL config defaults to enable Nested App Auth support and avoid overriding MSAL’s default authority.
- Allow Graph requests to use explicit, developer-supplied scopes (with a warning when falling back to
'.default'). - Treat Desktop broker
ApiContractViolationfailures fromacquireTokenSilentas interaction-required and fall back toacquireTokenPopup, with added unit tests.
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated 3 comments.
Show a summary per file
| File | Description |
|---|---|
| packages/client/src/msal-utils.ts | Adds broker-aware silent-token error handling and updates default MSAL configuration for NAA. |
| packages/client/src/msal-utils.spec.ts | Adds/updates unit tests for the new MSAL config and broker error fallback behavior. |
| packages/client/src/graph-utils.ts | Allows explicit Graph scopes to be supplied instead of hardcoding '.default', and warns on fallback. |
| packages/client/src/graph-utils.spec.ts | Extends tests to validate explicit scopes and the '.default' warning behavior. |
| packages/client/src/app.ts | Wires msalOptions.prewarmScopes through to Graph client scope selection and documents Desktop requirements. |
| packages/client/src/app.spec.ts | Updates expectations for MSAL config and Graph client wiring in App initialization tests. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
corinagum
force-pushed
the
cg/naa-desktop-repro
branch
from
June 15, 2026 17:30
fae4299 to
3fc0c9b
Compare
heyitsaamir
reviewed
Jun 15, 2026
lilyydu
approved these changes
Jun 15, 2026
heyitsaamir
approved these changes
Jun 15, 2026
corinagum
added a commit
that referenced
this pull request
Jun 15, 2026
## Release 2.0.13 Merges main into release for stable publish. ### Notable changes since 2.0.12 - fix(client): use explicit Graph scopes for Teams Desktop NAA compatibility (#616) - ci: switch publish pipeline to 1ES Official template for CodeQL/SDL (#607) - ci: add weekly SDL pipeline for CodeQL/CredScan compliance (#608) - Refresh teams.apps README (#604) - Reject unauthenticated when no credentials (#506) - fix(api): conditionally set citation encodingFormat based on text presence (#579) - Improvements to the Teams MCP server example (#597) - Bump MSAL Node to v5 (#603) - Merge root message entities in Activity (#590) - TeamsSDK: Correct imports and return types in misc. packages (#589) - Cache federated identity MSAL clients (#613) ### Release steps 1. Merge this PR 2. Trigger the [release pipeline](https://dev.azure.com/DomoreexpGithub/Github_Pipelines/_build?definitionId=52&_a=summary) for `release` branch with **Public** publish type 3. Bump version on main to `2.0.14-preview.{height}` 4. Create git tag and GitHub Release page
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #612 — Token acquisition fails on Teams Desktop but works on Teams Web.
Problem
On Teams Desktop, the OneAuth/WAM broker (via Nested App Auth) cannot resolve the
.defaultscope for Graph token requests the way browser MSAL does. The graph client in@microsoft/teams.clienthardcoded{ scopes: ['.default'] }, which causedApiContractViolationerrors ("declined scopes") on Desktop.Additionally, the MSAL config had
authority: ''(overriding MSAL's sensible default) and did not setsupportsNestedAppAuth: true.Fix
graph-utils.ts: Accept explicit scopes via agetGraphScopes()parameter instead of hardcoding.default. Logs a warning when falling back to.defaultto aid discoverability.app.ts: Pass the developer'sprewarmScopesthrough to the graph client so Graph calls use explicit scopes.msal-utils.ts: Remove emptyauthorityoverride (let MSAL use its defaultcommon), addsupportsNestedAppAuth: true, and handleApiContractViolationerrors from the Desktop broker as interaction-required (triggers popup fallback).Testing
/me) succeed on Desktopmsal-utils.tsandgraph-utils.tsNotes for reviewers
.defaultscope still works on Web, so this is backward compatible. IfprewarmScopesis not set, the graph client falls back to.defaultwith a warning.msalOptions.prewarmScopes.