尝试部署脚本失败后,如何用ARM模板自动化创建Azure企业应用?
用ARM模板自动化创建Azure企业应用
可以直接通过ARM模板实现Azure企业应用的自动化创建,以下是可行的方案:
最简ARM模板示例
通过用户分配托管标识创建企业应用(托管标识本质是特殊的服务主体,会自动在Azure AD中生成对应的企业应用条目):
{ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "resources": [ { "type": "Microsoft.ManagedIdentity/userAssignedIdentities", "apiVersion": "2023-01-31", "name": "my-enterprise-app", "location": "[resourceGroup().location]" }, // 可选:给企业应用分配资源权限 { "type": "Microsoft.Authorization/roleAssignments", "apiVersion": "2022-04-01", "name": "[guid(resourceGroup().id, 'contributor-role')]", "properties": { "roleDefinitionId": "[concat('/subscriptions/', subscription().subscriptionId, '/providers/Microsoft.Authorization/roleDefinitions/', 'b24988ac-6180-42a0-ab88-20f7382dd24c')]", "principalId": "[reference(resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', 'my-enterprise-app'), '2023-01-31').principalId]", "scope": "[resourceGroup().id]" }, "dependsOn": [ "[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', 'my-enterprise-app')]" ] } ], "outputs": { "enterpriseAppObjectId": { "type": "string", "value": "[reference(resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', 'my-enterprise-app'), '2023-01-31').principalId]" }, "enterpriseAppClientId": { "type": "string", "value": "[reference(resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', 'my-enterprise-app'), '2023-01-31').clientId]" } } }
关键说明
- 托管标识方案完全支持ARM原生部署,无需依赖额外脚本调用API
- 模板中默认包含了资源组参与者权限的分配,可根据需求替换
roleDefinitionId(比如读者权限ID为acdd72a7-3385-48ef-bd42-f606fba81ae7) - 部署后可通过输出获取企业应用的核心标识(对象ID、客户端ID),用于后续配置
部署命令(Azure CLI)
az deployment group create --resource-group <你的资源组名称> --template-file <模板文件名>.json
注意事项
- 执行部署的账号需要同时拥有Azure AD应用程序管理权限和目标资源组的写入权限
- 如果需要创建非托管标识的普通服务主体,ARM模板无法直接完成,需结合Microsoft Graph API,但托管标识方案已覆盖绝大多数企业应用自动化场景
内容的提问来源于stack exchange,提问作者Woitek1993
相关产品推荐
相关产品推荐

