You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Azure CLI在Azure AD B2C应用注册中添加作用域?

解决Azure AD B2C中使用Azure CLI添加作用域的错误

我帮你排查下这个问题,你遇到的Couldn't find 'api' in ''错误,核心原因是你的scopes.json结构不对——az ad app update命令的--set参数是直接针对应用对象的顶层属性,不需要在外层嵌套api键。

步骤1:修正scopes.json的结构

把原来JSON里外层的api对象去掉,直接保留oauth2PermissionScopes数组,同时修正拼写错误的deafult为default,修改后的文件内容如下:

[
  {
    "type": "User",
    "isEnabled": true,
    "adminConsentDisplayName": "default",
    "adminConsentDescription": "default",
    "id": "73a43c0e-9a5e-4646-9d1e-c56a43279f99",
    "value": "default",
    "userConsentDisplayName": "default",
    "userConsentDescription": "default"
  }
]

步骤2:重新运行更新命令

用修正后的JSON文件执行az ad app update,参数直接指向api.oauth2PermissionScopes:

az ad app update --id '你的应用ID' --set api.oauth2PermissionScopes=@scopes.json

备选方案:用az rest调用Graph API(B2C场景更可靠)

如果Azure CLI的az ad命令在B2C租户中出现兼容性问题,推荐直接调用Microsoft Graph API更新,这和你最初用az rest GET获取的应用结构完全匹配:

az rest --method PATCH \
  --uri https://graph.microsoft.com/v1.0/applications/你的应用ID \
  --body '{"api": {"oauth2PermissionScopes": [{"type": "User", "isEnabled": true, "adminConsentDisplayName": "default", "adminConsentDescription": "default", "id": "73a43c0e-9a5e-4646-9d1e-c56a43279f99", "value": "default", "userConsentDisplayName": "default", "userConsentDescription": "default"}]}}'

验证结果

更新完成后,用以下命令确认作用域是否添加成功:

az rest --method GET --uri https://graph.microsoft.com/v1.0/applications/你的应用ID

在返回的JSON中找到api.oauth2PermissionScopes字段,确认包含你配置的作用域即可。

内容的提问来源于stack exchange,提问作者Dilpreet

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 14:28:15