You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Entra ID自定义命名空间Schema Extension创建报错求助

Entra ID Schema Extension自定义命名空间报错:已验证域名仍提示未拥有命名空间

问题描述

测试Entra ID的Schema Extension与自定义命名空间功能时,使用租户中已完成验证的域名(d***demo.com)创建扩展,执行Graph API POST请求后返回报错:

Your organization must own the namespace d***demo.com as a part of one of the verified domains

已通过Graph API GET请求确认该域名在租户中状态为已验证,验证代码如下:

$Query = @{
        Method = "GET"
        Headers = @{
            Authorization = ("Bearer " + $JWT)
        }
        URI = "https://graph.microsoft.com/v1.0/domains/d***demo.com"
        ContentType = "application/json"
    }
Invoke-RestMethod @Query

创建Schema Extension的请求代码:

$Query = @{
        Method = "POST"
        Headers = @{
            Authorization = ("Bearer " + $JWT)
        }
        URI = "https://graph.microsoft.com/v1.0/schemaExtensions"
        ContentType = "application/json"
        Body = @{
            id = 'd***demo.com_CustomAttributes'
            description = 'Custom Attribute für das Entra ID'
            targetTypes = @(
                'Group'
            )
            properties = @(
                @{
                    name = 'SomeFancyAttribute1'
                    type = 'Boolean'
                }
            )
        } | ConvertTo-Json
    }
Invoke-RestMethod @Query

解决办法

1. 确认域名验证的完整状态

执行以下请求获取域名的详细验证信息,确保isVerified为True、state为verified,且域名是租户完全控制的(authenticationType为Managed或Federated均可):

$Query = @{
    Method = "GET"
    Headers = @{ Authorization = ("Bearer " + $JWT) }
    URI = "https://graph.microsoft.com/v1.0/domains/d***demo.com`?$select=id,isVerified,state,authenticationType"
    ContentType = "application/json"
}
Invoke-RestMethod @Query

2. 检查Schema Extension ID格式的准确性

  • 确保ID中的域名部分与租户中验证的域名完全一致,无通配符、隐藏字符或大小写差异(域名不区分大小写,但建议严格匹配)
  • 如果是测试时的域名遮挡,实际请求需填写完整的已验证域名,例如demodemo.com_CustomAttributes

3. 验证请求权限是否符合要求

创建Schema Extension需要以下权限之一:

  • 委托权限:Directory.AccessAsUser.All
  • 应用权限:Application.ReadWrite.All
    解析你的JWT令牌,确认scp(委托权限)或roles(应用权限)字段包含上述权限。

4. 改用Microsoft Graph PowerShell模块发起请求

手动构造HTTP请求可能存在格式问题,尝试用官方模块简化操作:

# 连接Graph并获取权限
Connect-MgGraph -Scopes "Application.ReadWrite.All"

# 创建Schema Extension
New-MgSchemaExtension -Id "demodemo.com_CustomAttributes" -Description "Custom Attribute für das Entra ID" -TargetTypes "Group" -Properties @(@{Name="SomeFancyAttribute1";Type="Boolean"})

5. 等待微软服务端数据同步

域名验证完成后,可能需要15-30分钟让数据在微软系统中同步,等待后再尝试创建操作。

若以上步骤均无法解决问题,建议提交微软技术支持工单,并提供域名验证状态截图、请求ID及报错详情。

内容的提问来源于stack exchange,提问作者user24801558

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 13:07:26