You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Azure Bicep或编程方式配置消费型Azure Logic App的AAD授权策略

如何用Bicep或编程方式配置消费型Azure Logic App的AAD授权策略?

问题描述

我在创建消费型Azure Logic App时,需要配置Azure Active Directory授权策略(对应门户路径:Logic App > Authorization > Add Policy),要设置策略名称、类型、Issuer、Audience及自定义声明。我尝试编写的Bicep代码中openAuthenticationPolicies部分无效,查阅官方文档未找到正确格式,导出ARM模板转换为Bicep后也看不到门户配置的策略。需要解决两个问题:

  1. 正确的Bicep配置方式
  2. 不用Bicep时,如何通过编程方式配置这些授权策略

我尝试的无效Bicep代码:

param name string = 'testlogicapptb'
param location string = 'Australia Southeast'

resource logicApp 'Microsoft.Logic/workflows@2019-05-01' = {
  name: name
  location: location
  properties: {
    definition: {
      '$schema': 'https://schema.management.azure.com/providers/Microsoft.Logic/schemas/2016-06-01/workflowdefinition.json#'
      contentVersion: '1.0.0.0'
    }
    parameters: {}
    accessControl: {
      triggers: {
        allowedCallerIpAddresses: [
          {
            addressRange: '123.1.1.1-123.1.1.1'
          }
        ]

        //Doesn't work - just trying anything
        openAuthenticationPolicies: {
          policies: {
            name: 'test'
            type: 'AAD'
            issuer: 'https://123/'
            audience: '123'
            claim: {
              name: 'role'
              value: '123'
            }
          }
        }
    }
    }
  }
}

解决方案

1. 正确的Bicep配置方式

消费型Logic App的AAD授权策略需嵌套在accessControl.triggers.openAuthenticationPolicies.policies数组中,属性名称和结构需严格匹配。核心注意点:

  • type必须设为OpenIdConnect(对应门户中的AAD类型)
  • issuer填写AAD租户的OpenID元数据地址,格式为https://login.microsoftonline.com/{tenantId}/v2.0
  • audience是Logic App触发URL中的client_id参数值(可从Logic App概述页的触发URL中提取)
  • claims为数组类型,支持多个自定义声明

完整Bicep示例:

param name string = 'testlogicapptb'
param location string = 'Australia Southeast'
param aadTenantId string = '<你的AAD租户ID>'
param logicAppAudience string = '<Logic App触发URL的client_id>'

resource logicApp 'Microsoft.Logic/workflows@2019-05-01' = {
  name: name
  location: location
  properties: {
    definition: {
      '$schema': 'https://schema.management.azure.com/providers/Microsoft.Logic/schemas/2016-06-01/workflowdefinition.json#'
      contentVersion: '1.0.0.0'
      triggers: {
        manual: {
          type: 'Request'
          kind: 'Http'
          inputs: {
            schema: {}
          }
        }
      }
    }
    parameters: {}
    accessControl: {
      triggers: {
        allowedCallerIpAddresses: [
          {
            addressRange: '123.1.1.1-123.1.1.1'
          }
        ]
        openAuthenticationPolicies: {
          policies: [
            {
              name: 'test-aad-policy'
              type: 'OpenIdConnect'
              issuer: 'https://login.microsoftonline.com/${aadTenantId}/v2.0'
              audience: [logicAppAudience]
              claims: [
                {
                  name: 'role'
                  value: 'LogicAppContributor'
                }
              ]
              metadata: {
                aadTenantId: aadTenantId
              }
            }
          ]
        }
      }
    }
  }
}

2. 非Bicep的编程配置方式

Azure CLI

使用az logic workflow update命令通过--set参数更新授权策略:

az logic workflow update \
  --name testlogicapptb \
  --resource-group <你的资源组名称> \
  --set properties.accessControl.triggers.openAuthenticationPolicies.policies="[{'name':'test-aad-policy','type':'OpenIdConnect','issuer':'https://login.microsoftonline.com/<租户ID>/v2.0','audience':['<client_id>'],'claims':[{'name':'role','value':'LogicAppContributor'}],'metadata':{'aadTenantId':'<租户ID>'}}]"

Azure PowerShell

通过Set-AzLogicApp命令结合哈希表配置访问控制:

$logicApp = Get-AzLogicApp -ResourceGroupName <资源组名称> -Name testlogicapptb

$accessControl = @{
  triggers = @{
    allowedCallerIpAddresses = @(@{addressRange = '123.1.1.1-123.1.1.1'})
    openAuthenticationPolicies = @{
      policies = @(
        @{
          name = 'test-aad-policy'
          type = 'OpenIdConnect'
          issuer = 'https://login.microsoftonline.com/<租户ID>/v2.0'
          audience = @('<client_id>')
          claims = @(@{name = 'role'; value = 'LogicAppContributor'})
          metadata = @{aadTenantId = '<租户ID>'}
        }
      )
    }
  }
}

$logicApp.Properties.AccessControl = $accessControl
Set-AzLogicApp -ResourceGroupName <资源组名称> -Name testlogicapptb -LogicApp $logicApp

REST API

发送PATCH请求到Logic App管理端点:

PATCH https://management.azure.com/subscriptions/<订阅ID>/resourceGroups/<资源组名称>/providers/Microsoft.Logic/workflows/testlogicapptb?api-version=2019-05-01
Content-Type: application/json

{
  "properties": {
    "accessControl": {
      "triggers": {
        "openAuthenticationPolicies": {
          "policies": [
            {
              "name": "test-aad-policy",
              "type": "OpenIdConnect",
              "issuer": "https://login.microsoftonline.com/<租户ID>/v2.0",
              "audience": ["<client_id>"],
              "claims": [{"name": "role", "value": "LogicAppContributor"}],
              "metadata": {"aadTenantId": "<租户ID>"}
            }
          ]
        }
      }
    }
  }
}

内容的提问来源于stack exchange,提问作者user27975968

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 20:24:54