ACS Calling SDK: Teams recipient policy lookup returns 401/5002 despite successful calls

Dariusz Cybulski 0 Reputation points
2026-09-23T14:56:50.8666667+00:00

We use @azure/communication-calling 1.43.1 to make Teams-to-Teams calls through an authenticated Teams user.

Calls connect and bidirectional audio/video work, but the SDK repeatedly fails to retrieve the recipient’s policy. We reproduced this with two licensed Teams recipients in the same tenant.

The SDK sends:

POST https://global.mtgw.prod.communication.microsoft.com/acsmt/v2/useraggregatepolicysettings/

The caller’s policy lookup returns HTTP 200. The recipient lookup returns HTTP 401, with this payload (recipient ID redacted):

{
  "id": "8:orgid:<recipient-entra-object-id>",
  "userPolicies": ["TeamsMeetingPolicy"],
  "userProperties": ["displayName"]
}

Response:

{
  "operationFailure": {
    "reason": "unknown",
    "code": 401,
    "subCode": 5002,
    "phrase": "UnAuthorized"
  }
}

The failure also produces an unhandled promise rejection from:

HttpRequestHelper.send

AcsMiddleTierPolicyService.requestUserPoliciesFromAcsMiddleTier

Our backend requests Teams.ManageCalls and Teams.ManageChats scopes and exchanges the caller’s Entra token using getTokenForTeamsUser. Token exchange and the caller’s policy lookup succeed.

We also inspected getRemoteParticipantProperties() in SDK versions 1.43.1 and 1.46.1. An isolated reproduction using the extracted method and a simulated request rejection shows that the inner rejection escapes while the returned promise remains pending. We have not tested actual calls on 1.46.1.

What specifically does subcode 5002 mean for this endpoint? Are there additional requirements for retrieving another same-tenant Teams user’s policy, or is this a known service/SDK issue?

Azure Communication Services
0 comments No comments

1 answer

Sort by: Most helpful
  1. Allan Solomon Mejia 10,145 Reputation points
    2026-09-23T19:08:34.08+00:00

    Hello @Dariusz Cybulski

    The documented requirements are the delegated Teams.ManageCalls and Teams.ManageChats permissions. Both are required to exchange a Teams user’s Microsoft Entra token for an ACS access token. Microsoft doesn’t document any additional permission needed to retrieve another same-tenant participant’s policy.

    Since token exchange succeeds, the caller-policy request returns 200, and the calls connect with working audio and video, the documented authentication requirements appear to be satisfied.

    However, subcode 5002 for the internal /acsmt/v2/useraggregatepolicysettings/ endpoint isn’t defined in Microsoft’s published ACS error-code documentation. I cannot find verified official documentation to confirm whether it represents a policy restriction or an internal service/SDK issue.

    The unhandled rejection may indicate an SDK error-handling issue, but you should first reproduce it during an actual call with version 1.46.1. If it persists, open an Azure support request and provide the UTC timestamp, client call ID, SDK/browser versions, verbose SDK logs, and the sanitized 200 versus 401/5002 request comparison. Microsoft recommends collecting the client call ID and SDK logs for service-side investigation.

    References:

    Microsoft Entra permissions for communication as a Teams user

    Set up and create access tokens for Teams users

    Troubleshooting in Azure Communication Services

    ACS Calling SDK troubleshooting codes


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.