You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何向SharePoint REST API批量传递PrincipalID分配读取权限?

批量为SharePoint列表项分配权限(Power Automate + SharePoint REST Batch请求)

问题场景

我用Power Automate做了个云流,流程是先获取分号分隔的Office 365安全组名称字符串,拆分后转成数组;再挨个获取每个组的PrincipalID,给指定列表项添加读取权限。但数组里组多的时候(比如5个),分步调用API效率太低,想一次性把所有组的PrincipalID传给SharePoint的roleassignments/addroleassignment端点完成权限分配。

之前单条请求的URI是:

_api/web/lists('*ListName*')/items(*ItemNumber*)/roleassignments/addroleassignment(PrincipalId=*PrincipleID*,roleDefId=1073741826)

实现方案:构造SharePoint REST Batch请求

用Power Automate的「发送HTTP请求」动作尝试Batch请求时,踩过404、MIME类型不匹配的坑,最终搞定了正确的请求体,成功实现批量分配。

正确的Batch请求体

--batch_1234
Content-Type: multipart/mixed; boundary="changeset_1234"

--changeset_1234
Content-Type: application/http
Content-Transfer-Encoding: binary

POST https://**.sharepoint.com/_api/web/lists/GetByTitle('GroupNamePrincipleID')/items(1)/roleassignments/addroleassignment(PrincipalId=2047,roleDefId=1073741826) HTTP/1.1

--changeset_1234
Content-Type: application/http
Content-Transfer-Encoding: binary

POST https://**.sharepoint.com/_api/web/lists/GetByTitle('GroupNamePrincipleID')/items(2)/roleassignments/addroleassignment(PrincipalId=2047,roleDefId=1073741826) HTTP/1.1

--changeset_1234
Content-Type: application/http
Content-Transfer-Encoding: binary

POST https://**.sharepoint.com/_api/web/lists/GetByTitle('GroupNamePrincipleID')/items(3)/roleassignments/addroleassignment(PrincipalId=2047,roleDefId=1073741826) HTTP/1.1

--changeset_1234--

--batch_1234--

核心注意点

  • Batch和Changeset的边界标识(比如batch_1234、changeset_1234)要唯一,避免冲突
  • 每个子请求必须携带Content-Type: application/http和Content-Transfer-Encoding: binary请求头
  • 替换请求URL中的实际站点域名、列表名称、列表项ID和PrincipalID
  • 严格遵循Batch请求的格式规范,否则容易触发MIME类型不匹配错误

内容的提问来源于stack exchange,提问作者microsoftdeveloperdesigner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 07:19:56