使用PnP PowerShell+注册应用访问SPO列表遇401未授权问题求助
微软逐步弃用用户名/密码认证方式,我尝试更新脚本以使用注册应用访问SharePoint Online列表,但始终遭遇401未授权错误,特向社区求助。
测试代码
Import-Module MSAL.PS Import-Module PnP.PowerShell $TenantId = "REDACTED" $siteUrl = "REDACTED" $listName = "People Who Are In" $Scope = "https://graph.microsoft.com/.default" # Clear-MsalTokenCache $Client = Get-PnPStoredCredential -Name IntranetAzureApp $authResult = Get-MsalToken -TenantId $tenantId -ClientId $client.UserName -ClientSecret $client.Password -Scopes $scope $AccessToken = $authResult.AccessToken Connect-PnPOnline $siteUrl -AccessToken $AccessToken Get-PnPList -Identity $listName
执行报错
Line | 26 | Get-PnPList -Identity "People Who Are In" | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ | The remote server returned an error: (401) | Unauthorized.
已尝试的方案及结果
- 权限配置:已配置Sites.FullControl.All、Sites.Manage.All、Sites.ReadWrite.All、Sites.Selected等权限(含通过POST请求为站点授权的操作),涵盖Microsoft Graph和SharePoint两类权限
- 修改Scope:尝试将Scope改为SharePoint站点地址(
https://REDACTED.sharepoint.com/.default),仍出现401错误,还触发AADSTS500011错误:
AADSTS500011: The resource principal named https://REDACTED.sharepoint.com/sites/Intranet was not found in the tenant named REDACTED This can happen if the application has not been installed by the administrator of the tenant or consented to by any user in the tenant. You might have sent your authentication request to the wrong tenant.
- 模块测试:尝试过Microsoft.Online.Sharepoint.Powershell模块,但它不支持使用AccessToken,无法满足脚本无人值守运行的需求
- API验证:通过PostMan调用Microsoft Graph API(
https://graph.microsoft.com/v1.0/sites/{{IntranetSiteId}}/lists/{{PWAI List ID}}及/items)可正常获取200响应与数据,且验证token包含所需角色:
"roles": ["Sites.FullControl.All"],
恳请各位提供问题原因排查方向或解决方案。
内容的提问来源于stack exchange,提问作者Ahren Bader-Jarvis
相关产品推荐
相关产品推荐

