You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure自助密码重置网站权限不足报错排查求助

问题描述

我正在搭建一个自助密码重置网站,让已登录/授权用户自行重置Azure AD密码。我当前拥有Cloud Application Administrator角色,以及以下Azure权限:

  • Directory.AccessAsUser.All
  • Directory.ReadWrite.All
  • email
  • Mail.Send
  • openid
  • profile
  • User.Read
  • User.ReadWrite.All
  • UserAuthenticationMethod.ReadWrite.All

我能完成用户认证并获取accessToken,但用这个token调用重置密码接口时报错。我试过切换到User Administrator角色,还是收到以下错误:

error: {
code: 'Authorization_RequestDenied',
message: 'Insufficient privileges to complete the operation.',
innerError: {
date: '2024-10-10T07:09:04',
'request-id': '7d1376c0-092b-4707-a4e8-cb480d15ae67',
'client-request-id': '7d1376c0-092b-4707-a4e8-cb480d15ae67'
}
}

想请教当前问题可能出在哪里?是否需要额外的权限或角色?

相关代码

密码重置代码

// Reset Password for authenticated users
const resetPassword = async (req, res) => {
  const { password, accessToken, userId } = req.body;
  console.log(
    "This is the user ID: " +
      userId +
      "New Password: " +
      password +
      "Token" +
      accessToken
  );

  // const decodedToken = jwt.decode(accessToken);
  // console.log("thisis the decoded token", decodedToken);
  try {
    const graphClientResponse = await axios.patch(
      `https://graph.microsoft.com/v1.0/users/${userId}`,
      {
        passwordProfile: {
          password: password,
          forceChangePasswordNextSignIn: false,
        },
      },
      {
        headers: {
          Authorization: `Bearer ${accessToken}`,
          "Content-Type": "application/json",
        },
      }
    );
    console.log(
      "Password reset for user with token:",
      graphClientResponse.data
    );
    res.status(200).json({ message: "Password reset successful!" });
  } catch (err) {
    console.error("Error resetting password:", err);
    res.status(500).json({ message: "Error resetting password." });
  }
};

Token获取代码

const getToken = async (req, res) => {
  const { code } = req.body;

  const tokenRequest = {
    client_id: msalConfig.auth.clientId,
    client_secret: msalConfig.auth.clientSecret,
    grant_type: "authorization_code",
    code: code,
    redirect_uri: "http://localhost:3000",
    scope:
      "openid profile email offline_access https://graph.microsoft.com/.default",
  };

  try {
    const response = await axios.post(
      `https://login.microsoftonline.com/${process.env.TENANT_ID}/oauth2/v2.0/token`,
      qs.stringify(tokenRequest),
      { headers: { "Content-Type": "application/x-www-form-urlencoded" } }
    );
    const accessToken = response.data.access_token;

    const graphResponse = await axios.get(
      "https://graph.microsoft.com/v1.0/me",
      {
        headers: { Authorization: `Bearer ${accessToken}` },
      }
    );

    const username = graphResponse.data.displayName;
    const id = graphResponse.data.id;
    res.status(200).json({
      success: true,
      accessToken: accessToken,
      username: username,
      id: id,
    });
  } catch (err) {
    console.error("Error exchanging authorization code:", err);
    res.status(500).json({
      success: false,
      message: "Error exchanging authorization code for token",
    });
  }
};

内容的提问来源于stack exchange,提问作者DipRaj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 10:29:56