You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何访问以Microsoft为身份提供商的Azure Function App?配置后未授权

Azure Function API 访问授权问题排查与解决

场景与已配置信息

我有一个Azure Function App,对外暴露API,需要支持两种访问方式:

  • 个人浏览器直接访问
  • MS Fabric工作区的Data Factory访问

身份提供商(Microsoft)配置

  • 身份提供商:Microsoft
  • 关联应用注册:SomeAppRegistration
  • 账户类型:当前租户(单租户)
  • 客户端密钥配置名称:MICROSOFT_PROVIDER_AUTHENTICATION_SECRET
  • 颁发者URL:空白
  • 允许的令牌受众:https://XXXXX.azurewebsites.net/.auth/login/aad/callback
  • 客户端应用要求:允许来自任何应用的请求(不推荐)
  • 身份要求:允许来自任何身份的请求
  • 租户要求:允许来自特定租户的请求

IAM角色分配

  • 所有者:my_own_email@email.com
  • Logic Apps Standard Reader:Fabric工作区(托管标识)

Function配置(function.json)

{
  "bindings": [
    {
      "authLevel": "anonymous",
      "type": "httpTrigger",
      "direction": "in",
      "name": "req",
      "methods": [
        "get",
        "post"
      ]
    },
    {
      "type": "http",
      "direction": "out",
      "name": "res"
    }
  ]
}

报错情况

  1. 浏览器访问报错:重定向后返回401错误

{"code":401,"message":"An error of type 'access_denied' occurred during the login process: 'AADSTS650056: Misconfigured application. This could be due to one of the following: the client has not listed any permissions for 'AAD Graph' in the requested permissions in the client's application registration. Or, the admin has not consented in the tenant. Or, check the application identifier in the request to ensure it matches the configured client application identifier. Or, check the certificate in the request to ensure it's valid. Please contact your admin to fix the configuration or consent on behalf of the tenant. Client app ID: XX. Trace ID: XX Correlation ID: XX Timestamp: XX'"}

  1. Fabric Data Factory访问报错:返回Unauthorized

问题排查与解决步骤

一、浏览器访问报错(AADSTS650056)处理

  1. 修正应用注册权限配置
    • 进入Entra ID的应用注册(SomeAppRegistration),切换到「API权限」页面
    • 添加Microsoft Graph的委托权限(如User.Read),并让租户管理员完成管理员同意;移除所有AAD Graph权限(该服务已废弃)
  2. 对齐应用注册与Function配置
    • 确认Function中配置的客户端ID与应用注册ID完全一致
    • 补全颁发者URL:单租户场景下设置为https://login.microsoftonline.com/{你的租户ID}/v2.0,不能留空
    • 修改令牌受众为应用注册的客户端ID,而非当前配置的回调URL(回调地址是登录跳转用的,不是令牌受众)
  3. 调整身份验证规则
    • 将客户端应用要求改为「仅允许指定的客户端应用」,添加浏览器对应的公共客户端ID(比如Edge浏览器ID:1fec8e78-bce4-4aaf-ab1b-5451cc387264)
    • 确认租户要求中指定的租户ID与应用注册所属租户一致

二、Fabric Data Factory访问报错(Unauthorized)处理

  1. 升级IAM角色权限
    • 把Fabric工作区的托管标识角色从「Logic Apps Standard Reader」改为Function App Contributor或Function App Reader,前者权限更适合API调用场景
  2. 配置Data Factory身份验证
    • 在Data Factory的HTTP活动中,选择「托管标识」作为身份验证类型
    • 设置资源URI为应用注册的客户端ID,而非Function的URL
  3. 验证权限生效
    • 确认托管标识已正确添加到Function App的IAM列表,等待10-15分钟让权限生效

三、通用配置修正

  1. 调整Function的authLevel
    • 当前authLevel设为anonymous会绕过AAD身份验证,需改为function或admin,确保身份验证规则生效
  2. 配置应用注册重定向URI
    • 在应用注册的「身份验证」页面,添加Function的回调URL:https://XXXXX.azurewebsites.net/.auth/login/aad/callback,类型设为「Web」
  3. 检查客户端密钥有效性
    • 确认应用注册中的客户端密钥未过期,且Function App的MICROSOFT_PROVIDER_AUTHENTICATION_SECRET配置项已正确存储该密钥

内容的提问来源于stack exchange,提问作者tsorn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 15:54:52