Skip to content

2.35 WAM Disablement Is Non-Functional #3518

Description

@nkasco

Describe the bug

The WAM disablement when using a custom ClientId appears to be non-functional. If I run Connect-MgGraph normally I get WAM (as expected), and when I pass a custom ClientId the cmdlet hangs and times out after 120 seconds. The browser window is not hidden behind anything.

Appears to be the same behavior in both PowerShell 7.5.4 as well as Windows PowerShell 5.1.

Reconfirmed that 2.33 is working properly (i.e. indicating that the client PC isn't blocking anything along the way)

This was supposed to be fixed in #3505

Expected behavior

Auth in browser window

How to reproduce

Set-MgGraphOption -DisableLoginByWAM $true
$ClientId = ""
$TenantId = ""
Connect-MgGraph -ClientId $ClientId -TenantId $TenantId

Error: Connect-MgGraph: Authentication timed out after 120 seconds due to inactivity. Please try again.
(Windows PowerShell presented a slightly different error: connect-mgGraph : InteractiveBrowserCredential authentication failed: An error occurred when writing to a listener.)

SDK Version

2.35

Latest version known to work for scenario above?

2.33

Known Workarounds

No response

Debug output

Click to expand log ```
</details>


### Configuration

_No response_

### Other information

_No response_

Activity

  1. j0eyv commented on Feb 2, 2026

    @j0eyv

    Can confirm the same behavior. Been testing the entire night coming to the same conclusion.

  2. jonade commented on Feb 3, 2026

    @jonade

    Can confirm that using both the -ClientId and -TenantId parameters causes the weird hanging behaviour in 2.35.0.

    However running it with only -ClientId works for me, and I do get an auth dialog appear. I can't actually connect because I get an error that "Usage of the /common endpoint is not supported" but that is obviously a different error.

    Edit: I take back my comment, on second connections even using -ClientId by itself no longer works. It only worked on the first attempt, where it showed the account picker dialog. Even closing and reopening PowerShell, it no longer works.

  3. FabienTschanz commented on Feb 4, 2026

    @FabienTschanz
    Contributor

    Also confirming from my side. Same steps as above, no hidden windows or anything. Running it with debug gives the following output (in PowerShell 7.5.4):

    ❯ Set-MgGraphOption -DisableLoginByWAM $true
    ❯ Connect-MgGraph -ClientId $clientId -TenantId $tenantId -Debug
    DEBUG: InteractiveBrowserCredential.Authenticate invoked. Scopes: [ User.Read ] ParentRequestId:
    DEBUG: Executing interactive authentication workflow via Task.Run.
    # Timeout after 120 seconds - Nothing in between these lines otherwise. 
    DEBUG: InteractiveBrowserCredential.Authenticate was unable to retrieve an access token. Scopes: [ User.Read ] ParentRequestId:  Exception: System.OperationCanceledException (0x8013153b): The operation was canceled.
    DEBUG: False MSAL 4.78.0.0 MSAL.CoreCLR .NET 9.0.10 Microsoft Windows 10.0.26200 [2026-02-04 13:43:23Z - c5e9e065-3409-4faf-9d2f-e2af2da6e155] MSAL MSAL.CoreCLR with assembly version '4.78.0.0'. CorrelationId(c5e9e065-3409-4faf-9d2f-e2af2da6e155)
  4. ramsessanchez commented on Feb 4, 2026

    @ramsessanchez
    Contributor

    Hi all,
    I have merged a pr to address this issue. Leaving the issue open until the release is complete. Release should be complete around midnight PST, about 8 hours from the time of this comment. Apologies for this incomplete release, this should have been more properly tested manually before shipping. Be on the lookout for v2.35.1. Thanks for raising this issue.

  5. j0eyv commented on Feb 5, 2026

    @j0eyv

    Can confirm this now works as expected Ramses Sanchez-Hernandez (@ramsessanchez). Thanks for this quick fix!
    Can you confirm that DisableLoginByWAM is here to stay in the next releases?

  6. gavinbarron commented on Feb 5, 2026

    @gavinbarron
    Member

    Joey vldn (@j0eyv) thanks for the confirmation. I'm going to close this as completed now.

    To answer your question, we're not taking it away for the BYO AppId scenarios until WAM is properly supports run as other user scenarios, and we expect to be able to communicate more clearly as that change approaches.

  7. tkol2022 commented on Feb 5, 2026

    @tkol2022

    This is working for me now with 2.35.1. Thanks for taking the comments and the fix.

    Image Image
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

type:bugA broken experience

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions