如何获取集成账户(Integration Account)的SAS URL及访问凭证?
Integration Account访问凭据/令牌获取指南
核心说明
Integration Account没有像存储账户那样的独立访问令牌,它的访问权限完全依托Azure Active Directory(Azure AD)的身份体系管理,以下是几种合法获取凭据的方式:
1. 托管标识(推荐方案)
- 为Integration Account启用托管标识:
- 进入Azure门户的目标Integration Account资源
- 左侧菜单选择「标识」,启用系统分配标识,或添加用户分配标识
- 为该托管标识分配对应权限:比如给它添加「Logic App Integration Account Contributor」「Reader」等角色
- 调用相关API或流程时,通过托管标识向Azure AD请求令牌,令牌受众(audience)设为
https://management.azure.com或对应Integration Account的API端点
2. 服务主体(Service Principal)
- 在Azure AD中注册一个服务主体
- 为该服务主体分配Integration Account的相关角色
- 通过服务主体的客户端ID、密钥(或证书)请求Azure AD令牌,示例PowerShell命令:
$tenantId = "你的租户ID" $clientId = "服务主体客户端ID" $clientSecret = "服务主体客户端密钥" $resource = "https://management.azure.com" $tokenResponse = Invoke-RestMethod -Uri "https://login.microsoftonline.com/$tenantId/oauth2/token" -Method Post -Body @{ grant_type = "client_credentials" client_id = $clientId client_secret = $clientSecret resource = $resource } $accessToken = $tokenResponse.access_token
3. Logic Apps集成场景
如果是在Logic Apps中访问Integration Account,直接在连接器配置里选择「托管标识」或「服务主体」即可,无需手动获取令牌,平台会自动完成身份验证。
注:你提供的截图为Integration Account概览与API连接页面,这类页面不会直接展示访问令牌,因为所有身份验证逻辑都由Azure AD统一管控
内容的提问来源于stack exchange,提问作者Venura Siriwardhana
相关产品推荐
相关产品推荐

