无法访问Azure ML数据存储:缺失listsecrets权限问题求助
解决Azure ML工作区数据存储访问权限问题
你遇到的问题核心是Contributor角色默认不包含Microsoft.MachineLearningServices/workspaces/datastores/listsecrets/action权限——即使拥有Contributor权限,也无法获取数据存储的密钥来访问数据,因此触发错误提示。以下是具体解决方案:
解决方案1:通过Azure门户创建自定义角色并分配
- 登录Azure门户,定位到你的Azure Machine Learning工作区
- 进入访问控制(IAM) 页面,点击添加 -> 添加自定义角色
- 在基本信息标签页输入角色名称(比如“AML数据存储密钥访问”)和描述
- 切换到权限标签页,搜索
Microsoft.MachineLearningServices/workspaces/datastores/listsecrets/action,勾选该权限后点击下一步 - 完成角色创建后,回到访问控制(IAM) 页面,点击添加 -> 添加角色分配,选择刚创建的自定义角色,将其分配给你的用户账户或所在用户组
解决方案2:使用Azure CLI快速配置
- 创建自定义角色定义文件(例如
aml-datastore-role.json),内容如下:{ "Name": "AML Datastore Secrets Access", "Description": "Grants permission to list datastore secrets in Azure ML workspace", "Actions": [ "Microsoft.MachineLearningServices/workspaces/datastores/listsecrets/action" ], "AssignableScopes": [ "/subscriptions/{你的订阅ID}/resourceGroups/{你的资源组名称}/providers/Microsoft.MachineLearningServices/workspaces/{你的AML工作区名称}" ] } - 执行命令创建角色:
az role definition create --role-definition aml-datastore-role.json - 执行命令为用户分配角色:
az role assignment create --assignee {你的用户ID或UPN} --role "AML Datastore Secrets Access" --scope "/subscriptions/{你的订阅ID}/resourceGroups/{你的资源组名称}/providers/Microsoft.MachineLearningServices/workspaces/{你的AML工作区名称}"
注意事项
- 操作时需确保当前用户拥有Owner或Role Based Access Control Administrator权限,才能创建自定义角色和进行角色分配
- 权限分配后可能需要3-5分钟生效,刷新Azure ML门户页面后再尝试访问数据存储
内容的提问来源于stack exchange,提问作者MPathan
相关产品推荐
相关产品推荐

