用户分配托管标识的Principal Type是什么?角色分配报错求助
用户分配托管身份对应的principalType取值问题
在为存储账户添加角色分配时,使用用户分配托管身份,代码如下:
RoleAssignmentCreateOrUpdateContent roleData = new RoleAssignmentCreateOrUpdateContent( roleDefinitionId: new ResourceIdentifier(string.Concat("/subscriptions/", SubscriptionId, "/providers/Microsoft.Authorization/roleDefinitions/", roleId)), principalId: PrincipalId);
执行时遇到如下错误:
ERROR: {"error":{"code":"PrincipalNotFound","message":"Principal xxx does not exist in the directory xxx. Check that you have the correct principal ID. If you are creating this principal and then immediately assigning a role, this error might be related to a replication delay. In this case, set the role assignment principalType property to a value, such as ServicePrincipal, User, or Group. See https://aka.ms/docs-principaltype"}}
错误提示建议添加principalType属性,请问用户分配托管身份对应的principalType是User、Group还是ServicePrincipal?
用户分配托管身份对应的principalType是ServicePrincipal。
用户分配托管身份本质是Azure AD中的服务主体对象,指定该类型可以规避因目录复制延迟引发的PrincipalNotFound错误。
修改后的代码示例:
RoleAssignmentCreateOrUpdateContent roleData = new RoleAssignmentCreateOrUpdateContent( roleDefinitionId: new ResourceIdentifier(string.Concat("/subscriptions/", SubscriptionId, "/providers/Microsoft.Authorization/roleDefinitions/", roleId)), principalId: PrincipalId, principalType: PrincipalType.ServicePrincipal);
内容的提问来源于stack exchange,提问作者ranger
相关产品推荐
相关产品推荐

