You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Bicep中分配Microsoft Graph权限时遇身份验证错误的解决咨询

问题

我在Bicep中尝试创建用户分配的标识,随后使用Microsoft.Graph的Bicep新功能为该标识分配权限范围,代码如下:

resource sqlIdentity 'Microsoft.ManagedIdentity/userAssignedIdentities@2023-01-31' = {
  location: location
  name: 'id-sqlserver-${environment}'
}

resource graphPermissions 'Microsoft.Graph/oauth2PermissionGrants@v1.0' = {
  clientId: sqlIdentity.properties.clientId
  consentType: 'Principal'
  resourceId: sqlIdentity.id
  scope: 'User.Read.All GroupMember.Read.All Application.Read.All'
}

但收到错误提示:The identity of the calling application could not be established,即使拥有高权限的用户尝试操作也会出现相同错误。请问如何在Bicep中正确分配Microsoft Graph权限?

解决方案
  • 修正resourceId参数:当前代码里的resourceId填的是用户分配标识的ID,这是错误的。resourceId需要指定Microsoft Graph服务主体的固定ID:00000003-0000-0000-c000-000000000000,而非你创建的标识ID。
  • 补充principalId参数:当consentType设为Principal时,必须明确指定要授予权限的主体ID,也就是你创建的用户分配标识的principalId。
  • 确保部署身份权限足够:执行Bicep部署的身份(用户或服务主体)需要拥有Directory.Read.All权限,同时需具备Application Administrator或Cloud Application Administrator这类可同意权限的角色。

修正后的完整代码示例:

resource sqlIdentity 'Microsoft.ManagedIdentity/userAssignedIdentities@2023-01-31' = {
  location: location
  name: 'id-sqlserver-${environment}'
}

resource graphPermissions 'Microsoft.Graph/oauth2PermissionGrants@v1.0' = {
  clientId: sqlIdentity.properties.clientId
  consentType: 'Principal'
  resourceId: '00000003-0000-0000-c000-000000000000'
  scope: 'User.Read.All GroupMember.Read.All Application.Read.All'
  principalId: sqlIdentity.properties.principalId
}

内容的提问来源于stack exchange,提问作者Mike Cole

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 01:30:05