使用Graph API无法获取跨租户用户邮箱的解决方案咨询
Use the
emaildelegated permission scope
This scope is designed to access a user's email address and does not require admin consent. When you includeemailin your authentication request's scope list (alongsideopenidandprofile):- The ID token returned during the OAuth flow will include an
emailclaim containing the user's primary email address. - Calling the
https://graph.microsoft.com/v1.0/meendpoint will also return themailproperty in the response (provided the user has an associated email). - Example scope string:
openid profile email
- The ID token returned during the OAuth flow will include an
Extract email directly from the ID token
If you don't need additional user data from the Graph API, you can skip the/mecall entirely. Theemailclaim in the ID token (obtained after authenticating with theemailscope) already contains the user's email address, eliminating the need for an extra API request.
Note: Ensure the user you're authenticating has a valid email address associated with their account; otherwise, the email claim or mail property may not be present.
内容的提问来源于stack exchange,提问作者Rik

