如何使用Azure CLI在Azure AD B2C应用注册中添加作用域?
解决Azure AD B2C中使用Azure CLI添加作用域的错误
我帮你排查下这个问题,你遇到的Couldn't find 'api' in ''错误,核心原因是你的scopes.json结构不对——az ad app update命令的--set参数是直接针对应用对象的顶层属性,不需要在外层嵌套api键。
步骤1:修正scopes.json的结构
把原来JSON里外层的api对象去掉,直接保留oauth2PermissionScopes数组,同时修正拼写错误的deafult为default,修改后的文件内容如下:
[ { "type": "User", "isEnabled": true, "adminConsentDisplayName": "default", "adminConsentDescription": "default", "id": "73a43c0e-9a5e-4646-9d1e-c56a43279f99", "value": "default", "userConsentDisplayName": "default", "userConsentDescription": "default" } ]
步骤2:重新运行更新命令
用修正后的JSON文件执行az ad app update,参数直接指向api.oauth2PermissionScopes:
az ad app update --id '你的应用ID' --set api.oauth2PermissionScopes=@scopes.json
备选方案:用az rest调用Graph API(B2C场景更可靠)
如果Azure CLI的az ad命令在B2C租户中出现兼容性问题,推荐直接调用Microsoft Graph API更新,这和你最初用az rest GET获取的应用结构完全匹配:
az rest --method PATCH \ --uri https://graph.microsoft.com/v1.0/applications/你的应用ID \ --body '{"api": {"oauth2PermissionScopes": [{"type": "User", "isEnabled": true, "adminConsentDisplayName": "default", "adminConsentDescription": "default", "id": "73a43c0e-9a5e-4646-9d1e-c56a43279f99", "value": "default", "userConsentDisplayName": "default", "userConsentDescription": "default"}]}}'
验证结果
更新完成后,用以下命令确认作用域是否添加成功:
az rest --method GET --uri https://graph.microsoft.com/v1.0/applications/你的应用ID
在返回的JSON中找到api.oauth2PermissionScopes字段,确认包含你配置的作用域即可。
内容的提问来源于stack exchange,提问作者Dilpreet
相关产品推荐
相关产品推荐

