You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Java调用MS Graph的getAllSites()时遇AccessDenied错误求助

Java调用MS Graph getAllSites()时AccessDenied错误解决方案

问题概述

使用Java调用MS Graph的getAllSites()方法时触发权限拒绝错误,代码取自Microsoft Learn,目标是获取所有SharePoint站点并下载其中一个站点的文件。

代码示例

final UsernamePasswordCredential credential = new UsernamePasswordCredentialBuilder()
            .clientId(clientId).tenantId(tenantId).username(userName).password(password)
            .build();

final GraphServiceClient graphClient = new GraphServiceClient(credential, scopes);

GetAllSitesGetResponse getAllSitesGetResponse = graphClient.sites().getAllSites().get();

List<Site> value = getAllSitesGetResponse.getValue();

错误信息

Exception in thread "main" com.microsoft.graph.models.odataerrors.ODataError: Access denied
    at com.microsoft.graph.models.odataerrors.ODataError.createFromDiscriminatorValue(ODataError.java:36)
    at com.microsoft.kiota.serialization.JsonParseNode.getObjectValue(JsonParseNode.java:212)
    at com.microsoft.kiota.http.OkHttpRequestAdapter.lambda$throwIfFailedResponse$0(OkHttpRequestAdapter.java:674)
    at com.microsoft.kiota.ApiExceptionBuilder.<init>(ApiExceptionBuilder.java:26)
    at com.microsoft.kiota.http.OkHttpRequestAdapter.throwIfFailedResponse(OkHttpRequestAdapter.java:673)
    at com.microsoft.kiota.http.OkHttpRequestAdapter.send(OkHttpRequestAdapter.java:281)
    at com.microsoft.graph.sites.getallsites.GetAllSitesRequestBuilder.get(GetAllSitesRequestBuilder.java:60)
    at com.microsoft.graph.sites.getallsites.GetAllSitesRequestBuilder.get(GetAllSitesRequestBuilder.java:46)

当前依赖版本

<dependency>
    <groupId>com.microsoft.graph</groupId>
    <artifactId>microsoft-graph</artifactId>
    <version>6.13.0</version>
</dependency>

<dependency>
    <groupId>com.microsoft.graph</groupId>
    <artifactId>microsoft-graph-core</artifactId>
    <version>3.1.14</version>
</dependency>

解决方案

1. 确认权限配置

  • 权限类型与范围:getAllSites接口需要以下权限之一:
    • 委托权限:Sites.Read.All 或 Sites.ReadWrite.All(需用户或管理员同意)
    • 应用权限:Sites.Read.All(需管理员同意)
  • 权限授予状态:在Azure AD应用注册中,确保已为应用授予对应权限并完成管理员同意(应用权限或需要管理员同意的委托权限必须由管理员批准)。
  • Scopes参数验证:如果使用委托流(如当前的UsernamePasswordCredential),scopes需包含"https://graph.microsoft.com/Sites.Read.All";如果使用应用流,scopes应为["https://graph.microsoft.com/.default"]。

2. 调整认证方式

当前使用的UsernamePasswordCredential(ROPC流)存在限制:不支持MFA,部分租户可能禁用该流,且不推荐用于生产环境。如果是服务端应用,建议改用客户端凭据流,搭配应用权限:

final ClientSecretCredential credential = new ClientSecretCredentialBuilder()
    .clientId(clientId)
    .tenantId(tenantId)
    .clientSecret(clientSecret)
    .build();

final GraphServiceClient graphClient = new GraphServiceClient(credential, Collections.singletonList("https://graph.microsoft.com/.default"));

GetAllSitesGetResponse getAllSitesGetResponse = graphClient.sites().getAllSites().get();
List<Site> value = getAllSitesGetResponse.getValue();

3. 验证用户/应用权限

使用Graph Explorer测试:用相同的用户账号调用GET /sites/getAllSites,确认用户本身是否具备访问所有站点的权限;若使用应用权限,需确认应用已被授予对应权限。

4. 站点文件下载示例

获取站点后,可通过以下代码下载指定文件(需替换占位符为实际ID):

// 下载站点中指定文件
InputStream fileStream = graphClient.sites("{site-id}")
    .drives("{drive-id}")
    .items("{item-id}")
    .content()
    .get();

// 将文件流写入本地
Files.copy(fileStream, Paths.get("local-file-path"), StandardCopyOption.REPLACE_EXISTING);

内容的提问来源于stack exchange,提问作者Daemon_Demon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 12:34:57