Azure自助密码重置网站权限不足报错排查求助
问题描述
我正在搭建一个自助密码重置网站,让已登录/授权用户自行重置Azure AD密码。我当前拥有Cloud Application Administrator角色,以及以下Azure权限:
- Directory.AccessAsUser.All
- Directory.ReadWrite.All
- Mail.Send
- openid
- profile
- User.Read
- User.ReadWrite.All
- UserAuthenticationMethod.ReadWrite.All
我能完成用户认证并获取accessToken,但用这个token调用重置密码接口时报错。我试过切换到User Administrator角色,还是收到以下错误:
error: {
code: 'Authorization_RequestDenied',
message: 'Insufficient privileges to complete the operation.',
innerError: {
date: '2024-10-10T07:09:04',
'request-id': '7d1376c0-092b-4707-a4e8-cb480d15ae67',
'client-request-id': '7d1376c0-092b-4707-a4e8-cb480d15ae67'
}
}
想请教当前问题可能出在哪里?是否需要额外的权限或角色?
相关代码
密码重置代码
// Reset Password for authenticated users const resetPassword = async (req, res) => { const { password, accessToken, userId } = req.body; console.log( "This is the user ID: " + userId + "New Password: " + password + "Token" + accessToken ); // const decodedToken = jwt.decode(accessToken); // console.log("thisis the decoded token", decodedToken); try { const graphClientResponse = await axios.patch( `https://graph.microsoft.com/v1.0/users/${userId}`, { passwordProfile: { password: password, forceChangePasswordNextSignIn: false, }, }, { headers: { Authorization: `Bearer ${accessToken}`, "Content-Type": "application/json", }, } ); console.log( "Password reset for user with token:", graphClientResponse.data ); res.status(200).json({ message: "Password reset successful!" }); } catch (err) { console.error("Error resetting password:", err); res.status(500).json({ message: "Error resetting password." }); } };
Token获取代码
const getToken = async (req, res) => { const { code } = req.body; const tokenRequest = { client_id: msalConfig.auth.clientId, client_secret: msalConfig.auth.clientSecret, grant_type: "authorization_code", code: code, redirect_uri: "http://localhost:3000", scope: "openid profile email offline_access https://graph.microsoft.com/.default", }; try { const response = await axios.post( `https://login.microsoftonline.com/${process.env.TENANT_ID}/oauth2/v2.0/token`, qs.stringify(tokenRequest), { headers: { "Content-Type": "application/x-www-form-urlencoded" } } ); const accessToken = response.data.access_token; const graphResponse = await axios.get( "https://graph.microsoft.com/v1.0/me", { headers: { Authorization: `Bearer ${accessToken}` }, } ); const username = graphResponse.data.displayName; const id = graphResponse.data.id; res.status(200).json({ success: true, accessToken: accessToken, username: username, id: id, }); } catch (err) { console.error("Error exchanging authorization code:", err); res.status(500).json({ success: false, message: "Error exchanging authorization code for token", }); } };
内容的提问来源于stack exchange,提问作者DipRaj
相关产品推荐
相关产品推荐

