You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure自动化账户托管身份连接SharePoint Online Sites.Selected权限报错

托管身份结合Sites.Selected权限访问SharePoint列表报错解决

问题概述

Azure自动化账户已通过托管身份成功连接Azure和Exchange,但使用Sites.Selected权限操作SharePoint列表时触发错误:

[AccessDenied] : Either scp or roles claim need to be present in the token.

已完成的配置和排查:

  • 在Entra中为托管身份配置了Sites.Selected应用权限,且通过New-MgSitePermission为其分配了目标站点的read/write权限,可通过Graph Explorer确认权限生效
  • 本地ISE/VSCode中用相同参数可正常更新列表,但自动化Runbook中获取的token无任何scopes声明
  • Runbook中托管身份以Application ID登录,而权限配置绑定的是该身份的Object ID(无法为Application ID分配权限)

根因分析

Get-AzAccessToken获取的Graph token未包含应用权限的roles声明:托管身份作为服务主体,需通过client_credentials授权流程请求Graph API的应用权限token,而Get-AzAccessToken默认未正确触发该流程,导致token缺失必要权限声明。

解决方案

替换Runbook中的token获取逻辑,改用client_credentials流程直接获取应用权限token:

  1. 获取Graph应用权限token

    # 配置参数
    $tenantId = "你的租户ID"
    $managedIdentityClientId = "托管身份的Application ID"
    $resource = "https://graph.microsoft.com"
    
    # 请求token
    $authUri = "https://login.microsoftonline.com/$tenantId/oauth2/v2.0/token"
    $tokenBody = @{
        grant_type = "client_credentials"
        client_id  = $managedIdentityClientId
        scope      = "$resource/.default"
    }
    $tokenResponse = Invoke-RestMethod -Uri $authUri -Method Post -Body $tokenBody -ContentType "application/x-www-form-urlencoded"
    $accessToken = $tokenResponse.access_token
    
  2. 使用token连接MgGraph并操作列表

    # 导入模块并连接Graph
    Import-Module Microsoft.Graph.Authentication
    Connect-MgGraph -AccessToken ($accessToken | ConvertTo-SecureString -AsPlainText -Force)
    
    # 验证权限上下文
    (Get-MgContext).Scopes
    
    # 操作SharePoint列表
    $siteId = "domain.sharepoint.com,Guid1,Guid2"
    $listId = "ListIDGuid"
    $params = @{
        fields = @{
            DateTime   = (Get-Date).ToString()
            UserEmail  = "name@domain.com"
            LicenseType = "E3"
            Successful = "Yes"
        }
    }
    New-MgSiteListItem -SiteId $siteId -ListId $listId -BodyParameter $params
    

关键注意事项

  • 确保托管身份的Sites.Selected权限为应用权限(而非委派权限),服务主体仅支持应用权限
  • 站点权限分配时,New-MgSitePermission中grantedToIdentities.application.id需填写托管身份的Object ID,此配置无需修改
  • 确保自动化账户中安装的Microsoft Graph模块为最新稳定版,避免兼容性问题

内容的提问来源于stack exchange,提问作者Daniel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 18:15:54