在Bicep中分配Microsoft Graph权限时遇身份验证错误的解决咨询
问题
我在Bicep中尝试创建用户分配的标识,随后使用Microsoft.Graph的Bicep新功能为该标识分配权限范围,代码如下:
resource sqlIdentity 'Microsoft.ManagedIdentity/userAssignedIdentities@2023-01-31' = { location: location name: 'id-sqlserver-${environment}' } resource graphPermissions 'Microsoft.Graph/oauth2PermissionGrants@v1.0' = { clientId: sqlIdentity.properties.clientId consentType: 'Principal' resourceId: sqlIdentity.id scope: 'User.Read.All GroupMember.Read.All Application.Read.All' }
但收到错误提示:The identity of the calling application could not be established,即使拥有高权限的用户尝试操作也会出现相同错误。请问如何在Bicep中正确分配Microsoft Graph权限?
解决方案
- 修正
resourceId参数:当前代码里的resourceId填的是用户分配标识的ID,这是错误的。resourceId需要指定Microsoft Graph服务主体的固定ID:00000003-0000-0000-c000-000000000000,而非你创建的标识ID。 - 补充
principalId参数:当consentType设为Principal时,必须明确指定要授予权限的主体ID,也就是你创建的用户分配标识的principalId。 - 确保部署身份权限足够:执行Bicep部署的身份(用户或服务主体)需要拥有
Directory.Read.All权限,同时需具备Application Administrator或Cloud Application Administrator这类可同意权限的角色。
修正后的完整代码示例:
resource sqlIdentity 'Microsoft.ManagedIdentity/userAssignedIdentities@2023-01-31' = { location: location name: 'id-sqlserver-${environment}' } resource graphPermissions 'Microsoft.Graph/oauth2PermissionGrants@v1.0' = { clientId: sqlIdentity.properties.clientId consentType: 'Principal' resourceId: '00000003-0000-0000-c000-000000000000' scope: 'User.Read.All GroupMember.Read.All Application.Read.All' principalId: sqlIdentity.properties.principalId }
内容的提问来源于stack exchange,提问作者Mike Cole
相关产品推荐
相关产品推荐

