You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AI Studio数据索引遇ScriptExecution.StreamAccess.Authentication权限错误求助

问题描述

已完成以下配置仍无法在Azure AI Studio中正常使用自有Blob存储数据:

  • 作为存储账户所有者,为Azure AI Studio应用及自身用户配置了Reader、Storage Blob Data Reader、Storage Blob Data Contributor权限
  • 存储账户虚拟网络设置为「仅允许选定虚拟网络和IP地址访问」,已将自身公网IP加入白名单
  • 已授予AI Studio工作区对存储账户的资源实例访问权限
  • 在AI Studio内尝试了Account Key、SAS认证,开启了Use workspace managed identity for data preview选项

当前现象:可连接Blob存储创建新数据,但索引数据时出现权限错误:

Error Code: ScriptExecution.StreamAccess.Authentication
Native Error: error in streaming from input data sources
    StreamError(PermissionDenied(Some(This request is not authorized to perform this operation.)))
=> permission denied when access stream. Reason: Some(This request is not authorized to perform this operation.)
    PermissionDenied(Some(This request is not authorized to perform this operation.))
Error Message: Authentication failed when trying to access the stream. Make sure you have correct permissions set up. Ok(This request is not authorized to perform this operation.)| session_id=

直接向AI Studio上传文件时也报错:

The file(s) couldn't be uploaded, because the storage is behind a 
virtual network, the supplied credentials might not have access, or the
storage account permissions might not be set up correctly. If access 
was granted recently, it may take several minutes to update in the 
system - you can simply try again later.
排查方向
  • 验证IP白名单准确性
    确认添加的公网IP是当前实际使用的IP(可执行curl ifconfig.me查看),注意区分IPv4/IPv6,确保存储账户白名单的IP类型与实际匹配;同时检查存储账户网络设置中是否勾选「允许受信任的Microsoft服务访问此存储账户」,Azure AI Studio属于受信任服务,未勾选会导致访问受限。

  • 检查工作区托管标识权限
    确认AI Studio工作区的托管标识(而非用户或应用)是否被授予Storage Blob Data Contributor或Storage Blob Data Reader权限,且权限范围需覆盖目标存储账户或容器(仅资源组级别权限可能不生效);可在存储账户的IAM页面筛选托管标识,查看工作区标识的权限配置。

  • 确认SAS/Account Key有效性
    若使用SAS,需确保其包含所需的读取/写入权限、未过期,且资源范围为目标容器或Blob;若使用Account Key,确认密钥未被轮换或禁用,且在AI Studio中输入无误。

  • 排查网络规则冲突
    检查存储账户的防火墙规则是否存在冲突,比如是否有拒绝所有访问的规则覆盖了允许规则;可临时将存储账户网络设置改为「允许所有网络访问」,测试是否能正常操作,以此确认是否为VNet规则导致的问题。

  • 等待权限生效或刷新会话
    Azure IAM权限变更通常需要5-15分钟生效,若刚完成配置,等待后重试;同时尝试注销并重新登录AI Studio,确保会话权限已更新。

内容的提问来源于stack exchange,提问作者GKecheng

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 03:27:22