You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

尝试部署脚本失败后,如何用ARM模板自动化创建Azure企业应用?

用ARM模板自动化创建Azure企业应用

可以直接通过ARM模板实现Azure企业应用的自动化创建,以下是可行的方案:

最简ARM模板示例

通过用户分配托管标识创建企业应用(托管标识本质是特殊的服务主体,会自动在Azure AD中生成对应的企业应用条目):

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": [
    {
      "type": "Microsoft.ManagedIdentity/userAssignedIdentities",
      "apiVersion": "2023-01-31",
      "name": "my-enterprise-app",
      "location": "[resourceGroup().location]"
    },
    // 可选:给企业应用分配资源权限
    {
      "type": "Microsoft.Authorization/roleAssignments",
      "apiVersion": "2022-04-01",
      "name": "[guid(resourceGroup().id, 'contributor-role')]",
      "properties": {
        "roleDefinitionId": "[concat('/subscriptions/', subscription().subscriptionId, '/providers/Microsoft.Authorization/roleDefinitions/', 'b24988ac-6180-42a0-ab88-20f7382dd24c')]",
        "principalId": "[reference(resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', 'my-enterprise-app'), '2023-01-31').principalId]",
        "scope": "[resourceGroup().id]"
      },
      "dependsOn": [
        "[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', 'my-enterprise-app')]"
      ]
    }
  ],
  "outputs": {
    "enterpriseAppObjectId": {
      "type": "string",
      "value": "[reference(resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', 'my-enterprise-app'), '2023-01-31').principalId]"
    },
    "enterpriseAppClientId": {
      "type": "string",
      "value": "[reference(resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', 'my-enterprise-app'), '2023-01-31').clientId]"
    }
  }
}

关键说明

  • 托管标识方案完全支持ARM原生部署,无需依赖额外脚本调用API
  • 模板中默认包含了资源组参与者权限的分配,可根据需求替换roleDefinitionId(比如读者权限ID为acdd72a7-3385-48ef-bd42-f606fba81ae7)
  • 部署后可通过输出获取企业应用的核心标识(对象ID、客户端ID),用于后续配置

部署命令(Azure CLI)

az deployment group create --resource-group <你的资源组名称> --template-file <模板文件名>.json

注意事项

  • 执行部署的账号需要同时拥有Azure AD应用程序管理权限和目标资源组的写入权限
  • 如果需要创建非托管标识的普通服务主体,ARM模板无法直接完成,需结合Microsoft Graph API,但托管标识方案已覆盖绝大多数企业应用自动化场景

内容的提问来源于stack exchange,提问作者Woitek1993

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 07:52:39