Troubleshooting Graph API connectivity

This article covers the most common errors related to Graph API connectivity. 

Code: Authorization_RequestDenied Message: Insufficient privileges to complete the operation.

CodeTwo Office 365 Migration doesn't have the necessary permissions to perform that operation. Make sure to follow these steps in order to grant all the required permissions in your Entra ID (Azure AD).

The wrong application (public or confidential) is being used with this authentication flow.

You will get this error if you enter an incorrect Certificate thumbprint / Client secret (app password) in the Application details step, if that certificate / client secret no longer exists in your Entra ID, or if it has expired.

You can also try the following solutions:

  • synchronize the time on the machine where CodeTwo Office 365 Migration is installed with a time server,
  • use the Client secret credential instead of Certificate thumbprint in the case you registered the CodeTwo migration application in Entra ID manually.
AADSTS700016: Application with identifier '<Client ID>' was not found in the directory '<Tenant ID>'.

This error occurs if:

  • CodeTwo Office 365 Migration has been deleted from your Entra ID (Azure AD). If so, make sure to register it again (automatically or manually),
  • you have provided incorrect Client ID and/or Tenant ID in the Application details step of the server connection wizard. Make sure that you have provided correct registration details and try again.
  • the application has just been registered, but not all changes have been propagated in your Entra ID. Wait awhile and try configuring the connection again (in the server configuration wizard, click Back, then Next to return to the Configuration step and click Configure).
The SMTP address has no mailbox associated with it.

You will get this error if the email address provided in the Application details step of the server connection wizard is not mailbox-enabled (it is not assigned an Office 365 license). You will also get this message if the provided email address is from a different Office 365 tenant than the one determined by the Tenant ID.

ClientId is not a Guid.

The Client ID entered in the Application details step is not valid. A valid GUID has the following form: 12345678-1234-1234-1234-1234567890AB. Double-check the entered Client ID and try again.

The operation was canceled.

This is a timeout error message that you will receive if the provided Client ID is not identified with any application registered in your Entra ID (Azure AD). Provide the correct ID or check if the application under that ID still exists in the Entra ID. 

Tenant '<Tenant ID'> not found.

Make sure you have entered a correct Tenant ID of your Office 365 tenant. The Tenant ID can be found in your tenant's Microsodt Entra admin center, on the Home page under the name of your company.

The certificate used must have a key size of at least 2048 bits.

This error appears if you have registered CodeTwo Office 365 Migration manually in your Entra ID and used a certificate that contains a key that is shorter than 2048 bits. Use a different certificate that uses the necessary key or generate a client secret instead.

Problem not solved?

If you can't find the solution to your problem, try searching our Knowledge Base.

If you still need help, contact our Customer Service. We know our products inside out.

In this article

Was this information useful?