Azure应用注册权限问题:无法读取订阅与Entra全局管理员
问题描述
我推测自己缺少某个角色权限。我创建了一个采用证书认证的Azure应用注册,完成认证后希望能获取所有订阅,以便遍历每个订阅/资源组查找所有虚拟机(VM);同时还希望通过该证书获取Entra租户中的全局管理员。
创建应用注册的PowerShell代码
$cert = New-SelfSignedCertificate -CertStoreLocation "cert:\CurrentUser\My" -Subject $applicationName -KeySpec KeyExchange -NotAfter (Get-Date).AddYears(1) $keyValue = [System.Convert]::ToBase64String($cert.GetRawCertData()) # 在Entra中为应用分配证书 $sp = New-AzADServicePrincipal -DisplayName $applicationName -CertValue $keyValue -EndDate $cert.NotAfter -StartDate $cert.NotBefore Start-Sleep -Seconds 3 # 将证书导出为PFX文件 $cert | Export-PfxCertificate -FilePath $certFilePath -Password (ConvertTo-SecureString -String $certPassword -Force -AsPlainText)
为应用注册分配权限的PowerShell代码
$app = Get-AzADApplication -ApplicationId $sp.AppId $appObjectId = $app.Id # GraphAPI - Directory.Read.All # Add-AzADAppPermission -ObjectId $appObjectId -ApiId "00000003-0000-0000-c000-000000000000" -PermissionId "4e9b66a2-74a1-4d86-a0cb-1a01e40e7d77" # # Add-AzADAppPermission -ObjectId "55fad647-6f5d-489f-b85e-00f96406ee9b" -ApiId "00000003-0000-0000-c000-000000000000" -PermissionId "5f8c59db-677d-491f-a6b8-5f174b11ec1d" # 添加Microsoft Graph的Directory.Read.All权限(应用权限) Add-AzADAppPermission -ObjectId $appObjectId -ApiId "00000003-0000-0000-c000-000000000000" -PermissionId "aef1f2db-fc2a-4d63-bcf5-e9a7a7802c9b" # 添加Microsoft Graph的Directory.Read.All权限(委托权限) Add-AzADAppPermission -ObjectId $appObjectId -ApiId "00000003-0000-0000-c000-000000000000" -PermissionId "df021288-bdef-4463-88db-98f22de89214" # 添加Azure服务管理的Reader权限 Add-AzADAppPermission -ObjectId $appObjectId -ApiId "00000002-0000-0000-c000-000000000000" -PermissionId "b7d27f52-6659-42b8-8164-4a0e63a2c156"
内容的提问来源于stack exchange,提问作者Bigbear
相关产品推荐
相关产品推荐

