L28 · OAUTH 2.0
Read the error, not just the screen
Send a mismatched redirect URI and an unknown scope, then deny consent, and read each error.
Planned
Steps
Send an authorization request with a redirect URI your client did not register.
What the server will check: The request was refused without redirecting.
Ask for a scope that does not exist.
What the server will check: An invalid_scope error returned to the client.
Deny consent.
What the server will check: An access_denied error returned to the client.
When it opens
This lab is planned. It opens when these are in place:
- Lab setup and cleanup in your test tenant
- The lab callback page
The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.