You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何限制Azure Entra服务主体仅读取特定前缀的组权限?

解决Azure Entra服务主体仅读取特定前缀组的权限问题

要实现服务主体仅能读取名称以foo-开头的组,目前没有直接的内置窄权限,但可以通过以下两种方案实现最小权限控制:

方案一:管理单元(AU)+ 范围限定权限

这种方式适合需要固定管理特定组集合的场景:

  • 先创建一个管理单元,把所有名称以foo-开头的组批量添加到这个单元里(可以用PowerShell或Graph API批量导入,避免手动操作)
  • 给服务主体分配Group.Read.All或GroupMember.Read.All权限时,将权限范围设置为这个管理单元,而非整个目录。这样服务主体只能访问该单元内的组,无法触及其他目录组。

方案二:权限条件(Permissions Conditions)+ 内置权限

这种方式适合动态匹配组名称前缀的场景,无需手动维护组集合:

  • 在Azure Entra的应用注册中找到目标服务主体,添加Group.Read.All或GroupMember.Read.All应用权限
  • 点击权限旁边的「添加条件」,设置规则:组的displayName属性以"foo-"开头(操作选择「Starts with」,值填入foo-)
  • 完成管理员同意后,服务主体调用Graph API时,仅能访问符合前缀规则的组,其他组会返回权限不足的错误。

Python脚本示例(使用Microsoft Graph SDK)

确保安装依赖:

pip install msgraph-core azure-identity

脚本示例:

from azure.identity import ClientSecretCredential
from msgraph.core import GraphClient

# 配置服务主体信息
tenant_id = "你的租户ID"
client_id = "服务主体ID"
client_secret = "服务主体密钥"

# 获取凭证
credential = ClientSecretCredential(
    tenant_id=tenant_id,
    client_id=client_id,
    client_secret=client_secret
)

# 初始化Graph客户端
graph_client = GraphClient(credential=credential)

# 查询所有foo-开头的组及其成员
result = graph_client.get(
    "/groups?$filter=startswith(displayName,'foo-')&$expand=members"
)

# 处理返回结果
groups = result.json()
for group in groups.get('value', []):
    print(f"组名称: {group['displayName']}")
    print("成员列表:")
    for member in group.get('members', []):
        print(f"- {member['displayName']} ({member['userPrincipalName']})")

验证权限有效性

测试时可以尝试让服务主体访问一个非foo-开头的组,比如调用/groups/{非foo组ID}/members,如果返回403 Forbidden,说明权限限制生效。

内容的提问来源于stack exchange,提问作者Tyn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 04:55:07