Every API call returns 401 Unauthorized after the customer connects
Symptom: your customer completes the OAuth flow and the connection is created, but every read, write, and proxy call for that installation returns 401 Unauthorized. The installation UI may also get stuck while loading the customer’s objects and fields.
Why this happens: this is possibly due to invalid scopes. Dynamics rejects API calls if your provider app includes scopes that Dynamics doesn’t support, even if the OAuth flow succeeds. You may have added User.Read or other scopes that belong to the Microsoft Graph API, not the Microsoft Dynamics API. Microsoft uses the first scope it sees to decide which API to grant access to.
How to fix:
- In the Ampersand Dashboard, open Provider Apps and select your Dynamics provider app.
-
In the Scopes field, remove any Microsoft Graph scopes and keep only Dynamics scopes plus
offline_access:- Dynamics 365 CRM:
.defaultoruser_impersonation. - Business Central:
.default.
.defaultbecomeshttps://<instance>.api.<region>.dynamics.com/.default. For Business Central,.defaultbecomeshttps://api.businesscentral.dynamics.com/.default. If your integration needs a Dynamics scope other than these, contact support@withampersand.com. - Dynamics 365 CRM:
- Click Save Changes.
-
Ask each affected customer to reconnect. Tokens that were already issued are still for the wrong API, so the new scopes only take effect once the customer authorizes again. Your customer can re-authenticate in your product’s Ampersand UI: from the Manage tab of the Install integration component (see Update a connection; requires
@amp-labs/reactv2.7 or later), or with the reauthenticate option in the Connect provider component.

