Power Platform部署Azure DevOps:桌面流连接权限问题求助
问题背景
我有一个由定时Cloud Flow和Power Automate Desktop Flow组成的Power Platform解决方案,Cloud Flow的操作如下:
- 从SharePoint获取文件(使用SharePoint连接)
- 调用Desktop Flow(使用Desktop连接)
为了Azure DevOps自动化部署,需要将上述连接共享给Azure DevOps服务主体。目前能成功共享SharePoint连接,但无法共享Desktop连接,导致解决方案部署失败。我理解如果不共享连接,就没法实现自动化部署(已在设置文件中使用连接引用)。需要解决两个问题:
- 如何克服这个部署失败的挑战?
- 为什么共享Desktop连接会存在限制?
附加信息
导入解决方案的DevOps任务
- task: PowerPlatformImportSolution@2 displayName: 'importSolution' inputs: authenticationType: 'PowerPlatformSPN' PowerPlatformSPN: ${{ parameters.devOpsSPN }} SolutionInputFile: '$(Pipeline.Workspace)/_managed.zip' UseDeploymentSettingsFile: true DeploymentSettingsFile: '$(Pipeline.Workspace)/settings.json' AsyncOperation: true MaxAsyncWaitTime: '60' OverwriteUnmanagedCustomizations: true
部署时抛出的异常
Request failed with: Forbidden and error:
{"error":{"code":"ConnectionAuthorizationFailed","message":"The caller
with object id '3c4b71874' does not have the minimum
required permission to perform the requested operation on connection
'ec6e6506238' under API 'shared_uiflow'."}} and request
url
https://api.powerapps.com/providers/Microsoft.PowerApps/scopes/service/apis/shared_uiflow/connections/ec66238?api-version=2018-10-01&$expand=permissions($filter=maxAssignedTo('3c41874')&$filter=environment
eq '7e********f50'.
设置文件中的连接引用
"ConnectionReferences": [ { "LogicalName": "contoso_Desktop_Flow_ConnRef", "ConnectionId": "9fec************215a9", "ConnectorId": "/providers/Microsoft.PowerApps/apis/shared_uiflow" }, { "LogicalName": "contoso_Microsoft_Dataverse_ConnRef", "ConnectionId": "shared-commondataser-c46c-000-000-000-09f", "ConnectorId": "/providers/Microsoft.PowerApps/apis/shared_commondataserviceforapps" }, { "LogicalName": "contoso_SharePoint_ConnRef", "ConnectionId": "31ee90000000000000000000553a71d", "ConnectorId": "/providers/Microsoft.PowerApps/apis/shared_sharepointonline" }, { "LogicalName": "new_shareduiflow_45580", "ConnectionId": "9fecdd3c-0000-000-000-4b2717a215a9", "ConnectorId": "/providers/Microsoft.PowerApps/apis/shared_uiflow" } ]
注意:我们有一个可重用管道,在没有Desktop连接的场景下运行正常。
问题解答
一、为什么共享Desktop连接会存在限制?
Power Automate Desktop(shared_uiflow)的连接属于用户上下文绑定型连接,和SharePoint这类服务级连接有本质区别:
- Desktop连接关联的是创建者的Windows账户权限,依赖本地会话或特定用户身份验证信息,服务主体(SPN)没有对应的本地Windows会话,无法模拟用户执行Desktop Flow的本地操作。
- 平台对shared_uiflow连接的权限管控更严格,不支持直接共享给服务主体,因为服务主体无法满足Desktop Flow运行所需的交互式用户上下文要求。
二、克服挑战的解决方案
针对这个问题,有三种可行的解决路径:
方案1:使用托管身份配置Desktop连接
- 在目标Power Platform环境中,为Power Automate Desktop创建系统托管身份或用户分配托管身份。
- 用该托管身份重新创建Desktop连接,确保连接关联的是托管身份而非个人用户账户。
- 将Azure DevOps服务主体添加为该托管身份的权限所有者,允许其在部署时引用该连接。
- 更新部署设置文件中的
ConnectionId为新创建的托管身份连接ID。
方案2:部署后补全连接权限
如果无法使用托管身份,可拆分部署流程:
- 部署时暂时在settings.json中移除或注释掉shared_uiflow的连接引用,先完成其他组件的部署。
- 部署完成后,要么手动在Power Platform环境中为Azure DevOps服务主体授予Desktop连接的
CanUse权限;要么编写PowerShell脚本调用Power Platform Admin API批量授权:- 用
Get-PowerAppConnection获取目标Desktop连接的详细信息 - 用
Set-PowerAppConnectionRoleAssignment为服务主体分配权限
- 用
方案3:切换为无人值守Desktop Flow模式
如果Desktop Flow的操作不依赖本地资源,可转换为无人值守运行:
- 在Power Automate中配置Desktop Flow为无人值守模式,使用服务账户或托管身份验证。
- 重新创建支持服务主体访问的Desktop连接。
- 更新Cloud Flow中的Desktop Flow调用,改用新的无人值守连接。
内容的提问来源于stack exchange,提问作者user527614

