You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用App-Only身份验证在PowerShell访问MS Teams遇权限问题求助

使用App-Only身份验证访问Teams PowerShell时出现Access Denied错误

已按官方文档配置App-Only身份验证访问Microsoft Teams PowerShell,已将应用服务主体分配给Teams Administrator角色,但执行Get-CsTenant或Get-CsOnlineUser等命令时返回错误:Get-CsTenant : Access Denied.


已执行的操作

客户端密钥方式验证

$ClientSecret   = "…"
$ApplicationID = "00000000-0000-0000-0000-000000000000"
$TenantID = "YYYYYYYY-YYYY-YYYY-YYYY-YYYYYYYYYYYY"

$graphtokenBody = @{   
   Grant_Type    = "client_credentials"   
   Scope         = "https://graph.microsoft.com/.default"   
   Client_Id     = $ApplicationID   
   Client_Secret = $ClientSecret   
}

$graphToken = Invoke-RestMethod -Uri "https://login.microsoftonline.com/$TenantID/oauth2/v2.0/token" -Method POST -Body $graphtokenBody | Select-Object -ExpandProperty Access_Token

$teamstokenBody = @{   
   Grant_Type    = "client_credentials"   
   Scope         = "48ac35b8-9aa8-4d74-927d-1f4a14a0b239/.default"   
   Client_Id     = $ApplicationID   
   Client_Secret = $ClientSecret 
}

$teamsToken = Invoke-RestMethod -Uri "https://login.microsoftonline.com/$TenantID/oauth2/v2.0/token" -Method POST -Body $teamstokenBody | Select-Object -ExpandProperty Access_Token

Connect-MicrosoftTeams -AccessTokens @("$graphToken", "$teamsToken")

证书方式验证

尝试使用证书身份验证,连接成功:

Connect-MicrosoftTeams -CertificateThumbprint 6BE884E1F9EA98CBE6E75AC8206527F7D41D1388 -ApplicationId $clientId -TenantId $tenantId

连接返回结果:

Account                              Environment Tenant                               TenantId
-------                              ----------- ------                               --------
e3fc1b90-xxxx-xxxx-ae5c-xxxxxxxx AzureCloud  xxxxxxx-da60-xxxx-a2fd-xxxxxxxxx xxxxxxx-da60-xxxx-a2fd-xxxxxxxxxx.

已分配的应用权限

"scope":
profile
openid
email
https://graph.microsoft.com/AllSites.FullControl
https://graph.microsoft.com/AuditLog.Read.All
https://graph.microsoft.com/Directory.Read.All
https://graph.microsoft.com/Exchange.Manage
https://graph.microsoft.com/ExternalItem.Read.All
https://graph.microsoft.com/ExternalUserProfile.Read.All
https://graph.microsoft.com/Group.Read.All
https://graph.microsoft.com/GroupMember.Read.All
https://graph.microsoft.com/IdentityProvider.Read.All
https://graph.microsoft.com/Mail.Read
https://graph.microsoft.com/Mail.Read.Shared
https://graph.microsoft.com/Mail.ReadBasic
https://graph.microsoft.com/Mail.ReadBasic.Shared
https://graph.microsoft.com/Organization.Read.All
https://graph.microsoft.com/Policy.Read.All
https://graph.microsoft.com/PrivilegedAccess.Read.AzureAD
https://graph.microsoft.com/PrivilegedAccess.Read.AzureADGroup
https://graph.microsoft.com/PrivilegedAccess.Read.AzureResources
https://graph.microsoft.com/PrivilegedAccess.ReadWrite.AzureAD
https://graph.microsoft.com/PrivilegedAssignmentSchedule.Read.AzureADGroup
https://graph.microsoft.com/PrivilegedEligibilitySchedule.Read.AzureADGroup
https://graph.microsoft.com/RoleAssignmentSchedule.Read.Directory
https://graph.microsoft.com/RoleEligibilitySchedule.Read.Directory
https://graph.microsoft.com/RoleManagement.Read.All
https://graph.microsoft.com/RoleManagement.Read.Directory
https://graph.microsoft.com/RoleManagement.ReadWrite.Directory
https://graph.microsoft.com/RoleManagementPolicy.Read.AzureADGroup
https://graph.microsoft.com/RoleManagementPolicy.Read.Directory
https://graph.microsoft.com/RoleManagementPolicy.ReadWrite.Directory
https://graph.microsoft.com/SharePointTenantSettings.Read.All
https://graph.microsoft.com/Sites.FullControl.All
https://graph.microsoft.com/TeamSettings.Read.All
https://graph.microsoft.com/TeamsPolicyUserAssign.ReadWrite.All
https://graph.microsoft.com/TeamsUserConfiguration.Read.All
https://graph.microsoft.com/User.Read
https://graph.microsoft.com/User.Read.All"

配置建议

  1. 更新Teams PowerShell模块
    旧版本模块可能存在App-Only身份验证兼容性问题,执行命令更新到最新版本:
Update-Module -Name MicrosoftTeams -Force
  1. 确认角色分配生效
    Azure AD角色分配可能需要数分钟至数小时生效,可通过命令验证服务主体的角色分配状态:
Get-AzureADServiceAppRoleAssignment -ObjectId <服务主体对象ID>

或在Azure AD门户中直接检查角色分配是否已正确应用。

  1. 添加Teams服务的应用权限
    当前仅分配了Graph权限,部分Teams PowerShell命令需要Teams服务的专用应用权限:
  • 在Azure AD应用注册中,搜索并选择Microsoft Teams服务
  • 添加对应应用权限(如TeamSettings.ReadWrite.All、User.ReadWrite.All等,按需选择)
  • 点击"授予管理员同意"完成权限生效
  1. 验证令牌权限
    解码$teamsToken,检查roles声明是否包含Teams Administrator角色及所需应用权限。若令牌中无对应权限,需重新检查权限分配或令牌请求配置。

  2. 调整Teams令牌请求范围
    尝试显式指定Teams服务的权限范围,而非使用.default:

$teamstokenBody = @{   
   Grant_Type    = "client_credentials"   
   Scope         = "48ac35b8-9aa8-4d74-927d-1f4a14a0b239/TeamSettings.Read.All 48ac35b8-9aa8-4d74-927d-1f4a14a0b239/User.Read.All"   
   Client_Id     = $ApplicationID   
   Client_Secret = $ClientSecret 
}
  1. 检查条件访问策略
    确认租户中无针对服务主体的条件访问策略,阻止其访问Teams PowerShell,可在Azure AD门户的条件访问页面排查相关限制。

内容的提问来源于stack exchange,提问作者SlavaG

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 21:43:18