使用ARM模板+Deployment Scripts创建Azure企业应用遇权限不足,需配置哪些权限?
解决Deployment Scripts创建Azure企业应用的权限不足问题
所需权限说明
你遇到的Insufficient privileges错误,核心原因是当前使用的用户分配标识没有Azure Active Directory(Azure AD)中创建应用注册的权限。
要创建企业应用(对应Azure AD中的应用注册),该标识需要以下任一Azure AD目录角色:
- 应用程序开发人员:默认允许创建最多100个应用注册(租户可调整限制),满足常规场景需求。
- 应用程序管理员:拥有完全管理应用注册和企业应用的权限,适合需要更高操作权限的场景。
注意:这些是Azure AD层面的目录角色,并非Azure资源的RBAC角色(比如资源组的Reader/Contributor),无法通过ARM模板中的Microsoft.Authorization/roleAssignments资源分配——该资源仅用于管理Azure云资源的权限,不涉及Azure AD内部权限。
解决方案及修改后的ARM模板
步骤1:提前分配Azure AD角色(推荐方案)
登录Azure门户,按以下步骤给用户分配标识添加对应角色:
- 进入Azure Active Directory → 角色和管理员。
- 搜索并选择「应用程序开发人员」或「应用程序管理员」角色。
- 点击「添加成员」,搜索你的用户分配标识名称并完成添加。
步骤2:优化ARM模板
原模板中的Microsoft.Authorization/roleAssignments资源是冗余的(仅给标识分配了读取自身的RBAC权限,与创建AD应用无关),可直接移除。修改后的模板如下:
{ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "location": { "type": "string", "defaultValue": "[resourceGroup().location]", "metadata": { "description": "所有资源的部署位置" } }, "entAppName": { "type": "string", "metadata": { "description": "企业应用的名称" } }, "identityName": { "type": "string", "metadata": { "description": "用户分配标识的名称" } } }, "resources": [ { "type": "Microsoft.ManagedIdentity/userAssignedIdentities", "apiVersion": "2023-01-31", "name": "[parameters('identityName')]", "location": "[parameters('location')]" }, { "type": "Microsoft.Resources/deploymentScripts", "apiVersion": "2023-08-01", "name": "runShellScript", "location": "[parameters('location')]", "kind": "AzureCLI", "identity": { "type": "UserAssigned", "userAssignedIdentities": { "[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]": {} } }, "dependsOn": [ "[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]" ], "properties": { "azCliVersion": "2.9.1", "scriptContent": " az login --identity # 创建企业应用(Azure AD应用注册) az ad app create --display-name $1 ", "arguments": "[parameters('entAppName')]", "timeout": "PT5M", "cleanupPreference": "OnSuccess", "retentionInterval": "P1D" } } ] }
可选:自动分配Azure AD角色(需部署身份有高权限)
如果希望部署过程中自动给标识分配AD角色,可修改Deployment Script的脚本内容,调用Microsoft Graph API完成操作。注意:执行模板部署的身份需要拥有角色管理员或全局管理员权限,否则会再次触发权限不足错误。示例脚本修改如下:
az login --identity # 获取用户分配标识的Object ID IDENTITY_OBJECT_ID=$(az resource show --id "[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]" --query "properties.principalId" -o tsv) # 获取应用程序开发人员角色的模板ID ROLE_TEMPLATE_ID=$(az ad role definition list --display-name "Application Developer" --query "[0].id" -o tsv) # 给标识分配角色 az ad role assignment create --role $ROLE_TEMPLATE_ID --assignee-object-id $IDENTITY_OBJECT_ID --assignee-principal-type ServicePrincipal # 创建企业应用 az ad app create --display-name $1
将上述脚本替换到模板的scriptContent字段即可。
内容的提问来源于stack exchange,提问作者Woitek1993
相关产品推荐
相关产品推荐

