You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法访问Azure ML数据存储:缺失listsecrets权限问题求助

解决Azure ML工作区数据存储访问权限问题

你遇到的问题核心是Contributor角色默认不包含Microsoft.MachineLearningServices/workspaces/datastores/listsecrets/action权限——即使拥有Contributor权限,也无法获取数据存储的密钥来访问数据,因此触发错误提示。以下是具体解决方案:

解决方案1:通过Azure门户创建自定义角色并分配

  • 登录Azure门户,定位到你的Azure Machine Learning工作区
  • 进入访问控制(IAM) 页面,点击添加 -> 添加自定义角色
  • 在基本信息标签页输入角色名称(比如“AML数据存储密钥访问”)和描述
  • 切换到权限标签页,搜索Microsoft.MachineLearningServices/workspaces/datastores/listsecrets/action,勾选该权限后点击下一步
  • 完成角色创建后,回到访问控制(IAM) 页面,点击添加 -> 添加角色分配,选择刚创建的自定义角色,将其分配给你的用户账户或所在用户组

解决方案2:使用Azure CLI快速配置

  • 创建自定义角色定义文件(例如aml-datastore-role.json),内容如下:
    {
      "Name": "AML Datastore Secrets Access",
      "Description": "Grants permission to list datastore secrets in Azure ML workspace",
      "Actions": [
        "Microsoft.MachineLearningServices/workspaces/datastores/listsecrets/action"
      ],
      "AssignableScopes": [
        "/subscriptions/{你的订阅ID}/resourceGroups/{你的资源组名称}/providers/Microsoft.MachineLearningServices/workspaces/{你的AML工作区名称}"
      ]
    }
    
  • 执行命令创建角色:
    az role definition create --role-definition aml-datastore-role.json
    
  • 执行命令为用户分配角色:
    az role assignment create --assignee {你的用户ID或UPN} --role "AML Datastore Secrets Access" --scope "/subscriptions/{你的订阅ID}/resourceGroups/{你的资源组名称}/providers/Microsoft.MachineLearningServices/workspaces/{你的AML工作区名称}"
    

注意事项

  • 操作时需确保当前用户拥有Owner或Role Based Access Control Administrator权限,才能创建自定义角色和进行角色分配
  • 权限分配后可能需要3-5分钟生效,刷新Azure ML门户页面后再尝试访问数据存储

内容的提问来源于stack exchange,提问作者MPathan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 13:17:07