I am relatively new in Sharepoint and Azure, i got a task to recreate a case of logging to sharepoint online site using powershell with m365 cli and TenantID and AppID environmentals, so i need to log in using something like this:
$env:CLIMICROSOFT365_AADAPPID="someidkey"
$env:CLIMICROSOFT365_TENANT="sometenantidkey"
m365 login --authType password --userName "testuser@domain.onmicrosoft.com" --password "somepassword"
I know it works on ot her apps
As for now i created Application in Azure Active Directory
in authentication i added mobile and deskotp application and checked https://login.microsoftonline.com/common/oauth2/nativeclient
i allowed public client flows
in api permission i putted Sharepoint Delegated AllSites.Write I Used Assignment required for application and i assigned application to "testuser"
Lets call this app: "Update Sharepoint"
Then i went to my sharepoint online site, used /_layouts/15/AppInv.aspx to grant permission
putted in App ID: ID for "Update Sharepoit"
in App Domain: domain.onmicrosoft.com
in Redirect url: http://domain.onmicrosoft.com
and in xml request
<AppPermissionRequests><AppPermissionRequest Scope="http://sharepoint/content/sitecollection/web" Right="FullControl" /></AppPermissionRequests>
My user is native user so he has disabled mfa, and is in member group of sharepoint site
However i can still just log in using just login and password and update the sharepoint site, using powershell.
What am i missing? How can i restrict sharepoint site that it needs to accept TenantID and AppID