You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用API创建MS Fabric工作区时遭遇403禁止错误的排查求助

解决MS Fabric API创建工作区时的403 Forbidden错误

针对你遇到的403错误,需从以下关键配置点排查修正:

1. 替换委托权限为应用权限

你当前配置的是委托权限,但使用client_credentials授权流时,仅支持应用权限。操作步骤:

  • 进入Azure AD应用注册的API权限页面
  • 删除现有Workspace.ReadWrite.All委托权限
  • 添加该权限的应用权限版本
  • 点击授予管理员同意(需全局管理员或Fabric管理员操作)

2. 将服务主体添加到容量贡献者列表

由于创建工作区指定了capacityId,服务主体必须拥有目标容量的**容量贡献者(Capacity Contributor)**角色:

  • 进入Fabric管理门户,找到对应容量
  • 在容量的访问控制页面,添加服务主体并分配容量贡献者角色

3. 确认租户级工作区创建权限(可选)

若上述配置后仍报错,检查Fabric租户设置:

  • 进入Fabric管理员门户的工作区设置
  • 确认允许服务主体创建工作区选项已启用(默认启用,特殊租户限制需手动开启)

你的认证脚本

# Define Variables
$tokenUrl = "https://login.microsoftonline.com/**/oauth2/v2.0/token"
$scope= "https://api.fabric.microsoft.com/.default"

# Prompt for user credentials 
$authParams = @{
    "client_id"    = $env:clientId
    "scope"        = $scope
    "grant_type"   = "client_credentials"
    "client_secret"     = $env:client_secret
}

# Get Access Token
$response = Invoke-RestMethod -Method Post -Uri $tokenUrl -ContentType "application/x-www-form-urlencoded" -Body $authParams

# Extract and Output the Token
$accessToken = $response.access_token
Write-Output "Full Response: $($response | ConvertTo-Json -Depth 10)"

# Ensure access token is retrieved
if (-not $response.access_token) {
    Write-Error "Access token is empty."
    exit 1
}

# Store Access Token as a Pipeline Variable (for next task)
Write-Output "##vso[task.setvariable variable=accessToken;isSecret=true]$accessToken"

Write-Output "Stored Access Token Length: $($accessToken.Length)"

你的工作区创建脚本

# Define API Variables
$workspaceUrl = "https://api.fabric.microsoft.com/v1/workspaces"
$accessToken = "$(accessToken)"  # Retrieve token from pipeline variable

# Ensure Access Token is Available
if (-not $accessToken) {
    Write-Error "Access token is missing. Ensure authentication task ran successfully."
    exit 1
}

# Define Workspace Payload
$workspaceBody = @{
    "displayName" = "Salmans Workspace"
    "description" = "This is a test workspace created via API"
    "capacityId"  = "**" # Replace with your actual capacity ID
} | ConvertTo-Json -Depth 10

# Define Headers
$headers = @{
    "Authorization" = "Bearer $accessToken"
    "Content-Type"  = "application/json"
}

# Call API to Create Workspace
$workspaceResponse = Invoke-RestMethod -Method Post -Uri $workspaceUrl -Headers $headers -Body $workspaceBody

# Output Response
Write-Output "Workspace Creation Response: $($workspaceResponse | ConvertTo-Json -Depth 10)"

已配置的API权限截图

API权限截图


内容的提问来源于stack exchange,提问作者Salman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 19:52:38