You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Microsoft Graph API获取日历事件失败:租户GUID不存在错误排查

解决Microsoft Graph API调用时的OrganizationFromTenantGuidNotFound错误

问题概述

  • 使用Microsoft Graph API v1.0编写代码无法获取令牌,全网缺少v2.0版本添加日历事件的示例
  • 通过Postman集合能生成有效令牌,但调用https://graph.microsoft.com/v1.0/me/events接口时返回OrganizationFromTenantGuidNotFound错误
  • 已为应用配置日历全权限,且确认令牌有效,但调用日历相关API仍报错

错误响应详情

{
    "error": {
        "code": "OrganizationFromTenantGuidNotFound",
        "message": "The tenant for tenant guid 'f3fd3de8-d438-4470-b351-5a7dde989db8' does not exist.",
        "innerError": {
            "oAuthEventOperationId": "10aaa007-edfb-4d36-ab46-d68e51af1e28",
            "oAuthEventcV": "bFc6s7xHD3sZPpSDf6Ve5Q.1.1",
            "errorUrl": "https://aka.ms/autherrors#error-InvalidTenant",
            "requestId": "41ca535c-2339-4e95-8915-2f1cdda88231",
            "date": "2024-06-10T06:12:02"
        }
    }
}

当前使用的代码片段

授权URL

$url="https://login.microsoftonline.com/$row_comp->ol_tenant_id/oauth2/authorize?client_id=$row_comp->ol_client_id&response_type=code&redirect_uri=$url_auth&response_mode=query&scope=api://$row_comp->ol_client_id/Calendars.ReadWrite%20offline_access&state=12345";

获取令牌的CURL请求

$url = "https://login.microsoftonline.com/$tenant/oauth2/v2.0/token";

$data = [
    'client_id' => $clientId,
    'scope' => "Calendars.ReadBasic openid profile offline_access",
    'code' => $authorizationCode,
    'redirect_uri' => $redirectUri,
    'grant_type' => 'authorization_code',
    'client_secret' => $clientSecret
];

$options = [
    CURLOPT_URL => $url,
    CURLOPT_POST => true,
    CURLOPT_POSTFIELDS => http_build_query($data),
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => [
        'Content-Type: application/x-www-form-urlencoded'
    ],
];

$ch = curl_init();
curl_setopt_array($ch, $options);
$response = curl_exec($ch);
if(curl_errno($ch)) {
    $error_msg='1 :. Error:' . curl_error($ch);
}
curl_close($ch);

$responseData = json_decode($response, true);
$full_object['first_call']=json_decode($response);
if (isset($responseData['error'])) {
    $error_msg= "1 :. Error: " . $responseData['error_description'] . "
";
} else {
    if(isset($responseData['refresh_token']))
    {
        $ol_access_token_old=$responseData['access_token'];
        $ol_refresh_token_old=$responseData['refresh_token'];
        $accessToken = $responseData['access_token'];
        $refreshToken = $responseData['refresh_token'];
    }
}

刷新令牌代码

if($refreshToken!="")
{
    $url = "https://login.microsoftonline.com/$tenant/oauth2/v2.0/token";
    $params=[];
    $params['url']=$url;
    $params['clientId']=$clientId;
    $params['refreshToken']=$refreshToken;
    $params['clientSecret']=$clientSecret;
    $res_data=RefreshToeknOutlook($params);

    $full_object['second_call']=$res_data['full_res'];
    $error_msg=$res_data['error_msg'];
        
    $ol_access_token_new=$res_data['ol_access_token_new'];
    $ol_refresh_token_new=$res_data['ol_refresh_token_new'];
    $ol_token_expiry_date=$res_data['ol_token_expiry_date'];

    if($ol_access_token_new!="" && $error_msg=="")
    {
        $dt=date("Y-m-d H:i:s");
        $ol_token_expiry_date=date("Y-m-d H:i:s",strtotime($dt." +".$ol_token_expiry_date." seconds"));
        $sql_update="update tbl_admin set ol_authorization_code='".$db->real_escape_string($code)."'";
        $sql_update.=",ol_access_token_old='".$db->real_escape_string($ol_access_token_old)."'";
        $sql_update.=",ol_refresh_token_old='".$db->real_escape_string($ol_refresh_token_old)."'";
        $sql_update.=",ol_access_token_new='".$db->real_escape_string($ol_access_token_new)."'";
        $sql_update.=",ol_refresh_token_new='".$db->real_escape_string($ol_refresh_token_new)."'";
        $sql_update.=",ol_token_expiry_date='".$db->real_escape_string($ol_token_expiry_date)."'";
        $sql_update.=",ol_log_text='".$db->real_escape_string(json_encode($full_object))."'";
        $sql_update.=" where id='".$row_comp->id."'";
        
        $db->query($sql_update);
    }
}

解决方法

  1. 校验租户ID有效性

    • 确认$row_comp->ol_tenant_id和$tenant变量对应的租户GUID是否正确,可在Azure门户的Azure Active Directory -> 概述中获取官方租户ID
    • 若使用个人Microsoft账户(非工作/学校账户),授权和令牌请求需将租户ID改为common,因为个人账户不属于特定组织租户
  2. 统一作用域格式

    • 当前授权URL使用自定义API作用域api://$row_comp->ol_client_id/Calendars.ReadWrite,与获取令牌时的Calendars.ReadBasic不匹配,需改为Microsoft Graph标准作用域
    • 修正后的授权URL作用域:scope=https://graph.microsoft.com/Calendars.ReadWrite%20https://graph.microsoft.com/offline_access
    • 获取令牌时的scope改为:"https://graph.microsoft.com/Calendars.ReadWrite https://graph.microsoft.com/offline_access openid profile"
  3. 验证令牌受众

    • 解码access_token(用JWT解析工具),检查aud字段是否为https://graph.microsoft.com,若不是则说明作用域配置错误,令牌无法用于Graph API调用
  4. 确认应用注册配置

    • 若面向个人Microsoft账户,需在Azure门户应用注册中设置支持的账户类型为“任何组织目录中的账户和个人Microsoft账户”
    • 确保已添加Microsoft Graph的Calendars.ReadWrite委托权限,并完成管理员同意(工作/学校账户场景)

内容的提问来源于stack exchange,提问作者Nilesh Daldra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 18:44:52