You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure MSAL中服务主体认证运行Data Factory管道的正确Scope是什么?

问题解决:Azure Data Factory REST API 401未授权问题

核心原因:Scope设置错误

你当前使用的https://graph.microsoft.com/.default是Microsoft Graph API的权限范围,但你调用的是Azure管理API(management.azure.com),令牌权限范围与目标API不匹配,导致401未授权。

正确的Scope

调用Azure Data Factory管理API时,需使用Azure管理服务的默认scope:

scopes=["https://management.azure.com/.default"]

修改后的认证代码

将认证类中的scope替换为上述值即可:

class MsalAuth(Auth):
    def __init__(self, parameters: dict):
        self.sp_client_id = parameters["sp_client_id"]
        self.sp_client_secret = parameters["sp_client_secret"]
        self.tenant_id = parameters["tenant_id"]
        authority = f"https://login.microsoftonline.com/{self.tenant_id}"

        app = msal.ConfidentialClientApplication(
            self.sp_client_id,
            authority=authority,
            client_credential=self.sp_client_secret
        )
        # 替换为正确的Azure管理API scope
        result = app.acquire_token_for_client(scopes=["https://management.azure.com/.default"])
        self.bearer_token = result['access_token']

    def get_headers(self):
        headers = {"Authorization": f"Bearer {self.bearer_token}"}
        return headers

补充说明

Azure资源管理类API(包括Data Factory)的client credential flow权限范围,统一遵循https://<服务根域名>/.default格式,这里的服务根域名就是你调用的API前缀management.azure.com。

同时请确认:你的服务主体已被正确授予Data Factory Contributor角色,且角色作用范围覆盖目标Data Factory所在的订阅、资源组或工厂资源,这是避免401的必要前提。


内容的提问来源于stack exchange,提问作者Shaun Ryan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 18:27:33