You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用ARM模板+Deployment Scripts创建Azure企业应用遇权限不足,需配置哪些权限?

解决Deployment Scripts创建Azure企业应用的权限不足问题

所需权限说明

你遇到的Insufficient privileges错误,核心原因是当前使用的用户分配标识没有Azure Active Directory(Azure AD)中创建应用注册的权限。

要创建企业应用(对应Azure AD中的应用注册),该标识需要以下任一Azure AD目录角色:

  • 应用程序开发人员:默认允许创建最多100个应用注册(租户可调整限制),满足常规场景需求。
  • 应用程序管理员:拥有完全管理应用注册和企业应用的权限,适合需要更高操作权限的场景。

注意:这些是Azure AD层面的目录角色,并非Azure资源的RBAC角色(比如资源组的Reader/Contributor),无法通过ARM模板中的Microsoft.Authorization/roleAssignments资源分配——该资源仅用于管理Azure云资源的权限,不涉及Azure AD内部权限。

解决方案及修改后的ARM模板

步骤1:提前分配Azure AD角色(推荐方案)

登录Azure门户,按以下步骤给用户分配标识添加对应角色:

  1. 进入Azure Active Directory → 角色和管理员。
  2. 搜索并选择「应用程序开发人员」或「应用程序管理员」角色。
  3. 点击「添加成员」,搜索你的用户分配标识名称并完成添加。

步骤2:优化ARM模板

原模板中的Microsoft.Authorization/roleAssignments资源是冗余的(仅给标识分配了读取自身的RBAC权限,与创建AD应用无关),可直接移除。修改后的模板如下:

{
    "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
    "contentVersion": "1.0.0.0",
    "parameters": {
        "location": {
            "type": "string",
            "defaultValue": "[resourceGroup().location]",
            "metadata": {
                "description": "所有资源的部署位置"
            }
        },
        "entAppName": {
            "type": "string",
            "metadata": {
                "description": "企业应用的名称"
            }
        },
        "identityName": {
            "type": "string",
            "metadata": {
                "description": "用户分配标识的名称"
            }
        }
    },
    "resources": [
        {
            "type": "Microsoft.ManagedIdentity/userAssignedIdentities",
            "apiVersion": "2023-01-31",
            "name": "[parameters('identityName')]",
            "location": "[parameters('location')]"
        },
        {
            "type": "Microsoft.Resources/deploymentScripts",
            "apiVersion": "2023-08-01",
            "name": "runShellScript",
            "location": "[parameters('location')]",
            "kind": "AzureCLI",
            "identity": {
                "type": "UserAssigned",
                "userAssignedIdentities": {
                    "[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]": {}
                }
            },
            "dependsOn": [
                "[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]"
            ],
            "properties": {
                "azCliVersion": "2.9.1",
                "scriptContent": "
                    az login --identity
                    # 创建企业应用(Azure AD应用注册)
                    az ad app create --display-name $1
                ",
                "arguments": "[parameters('entAppName')]",
                "timeout": "PT5M",
                "cleanupPreference": "OnSuccess",
                "retentionInterval": "P1D"
            }
        }
    ]
}

可选:自动分配Azure AD角色(需部署身份有高权限)

如果希望部署过程中自动给标识分配AD角色,可修改Deployment Script的脚本内容,调用Microsoft Graph API完成操作。注意:执行模板部署的身份需要拥有角色管理员或全局管理员权限,否则会再次触发权限不足错误。示例脚本修改如下:

az login --identity
# 获取用户分配标识的Object ID
IDENTITY_OBJECT_ID=$(az resource show --id "[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]" --query "properties.principalId" -o tsv)
# 获取应用程序开发人员角色的模板ID
ROLE_TEMPLATE_ID=$(az ad role definition list --display-name "Application Developer" --query "[0].id" -o tsv)
# 给标识分配角色
az ad role assignment create --role $ROLE_TEMPLATE_ID --assignee-object-id $IDENTITY_OBJECT_ID --assignee-principal-type ServicePrincipal
# 创建企业应用
az ad app create --display-name $1

将上述脚本替换到模板的scriptContent字段即可。

内容的提问来源于stack exchange,提问作者Woitek1993

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 16:05:09