Azure自动化账户托管身份连接SharePoint Online Sites.Selected权限报错
问题概述
Azure自动化账户已通过托管身份成功连接Azure和Exchange,但使用Sites.Selected权限操作SharePoint列表时触发错误:
[AccessDenied] : Either scp or roles claim need to be present in the token.
已完成的配置和排查:
- 在Entra中为托管身份配置了Sites.Selected应用权限,且通过
New-MgSitePermission为其分配了目标站点的read/write权限,可通过Graph Explorer确认权限生效 - 本地ISE/VSCode中用相同参数可正常更新列表,但自动化Runbook中获取的token无任何scopes声明
- Runbook中托管身份以Application ID登录,而权限配置绑定的是该身份的Object ID(无法为Application ID分配权限)
根因分析
Get-AzAccessToken获取的Graph token未包含应用权限的roles声明:托管身份作为服务主体,需通过client_credentials授权流程请求Graph API的应用权限token,而Get-AzAccessToken默认未正确触发该流程,导致token缺失必要权限声明。
解决方案
替换Runbook中的token获取逻辑,改用client_credentials流程直接获取应用权限token:
获取Graph应用权限token
# 配置参数 $tenantId = "你的租户ID" $managedIdentityClientId = "托管身份的Application ID" $resource = "https://graph.microsoft.com" # 请求token $authUri = "https://login.microsoftonline.com/$tenantId/oauth2/v2.0/token" $tokenBody = @{ grant_type = "client_credentials" client_id = $managedIdentityClientId scope = "$resource/.default" } $tokenResponse = Invoke-RestMethod -Uri $authUri -Method Post -Body $tokenBody -ContentType "application/x-www-form-urlencoded" $accessToken = $tokenResponse.access_token使用token连接MgGraph并操作列表
# 导入模块并连接Graph Import-Module Microsoft.Graph.Authentication Connect-MgGraph -AccessToken ($accessToken | ConvertTo-SecureString -AsPlainText -Force) # 验证权限上下文 (Get-MgContext).Scopes # 操作SharePoint列表 $siteId = "domain.sharepoint.com,Guid1,Guid2" $listId = "ListIDGuid" $params = @{ fields = @{ DateTime = (Get-Date).ToString() UserEmail = "name@domain.com" LicenseType = "E3" Successful = "Yes" } } New-MgSiteListItem -SiteId $siteId -ListId $listId -BodyParameter $params
关键注意事项
- 确保托管身份的Sites.Selected权限为应用权限(而非委派权限),服务主体仅支持应用权限
- 站点权限分配时,
New-MgSitePermission中grantedToIdentities.application.id需填写托管身份的Object ID,此配置无需修改 - 确保自动化账户中安装的Microsoft Graph模块为最新稳定版,避免兼容性问题
内容的提问来源于stack exchange,提问作者Daniel
相关产品推荐
相关产品推荐

