You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何限制使用Azure AD Graph API的OAuth应用可见的Azure AD组范围

Great question—locking down a service's access to only specific Azure AD groups (instead of trusting the service to filter them) is a smart, secure approach. Since the service uses Azure AD Graph API, here are two reliable ways to enforce this restriction from your side:

1. Restrict Application Permissions to Specific Groups

Azure AD lets you narrow down broad application permissions (like Group.Read.All) to only apply to a subset of your groups. Here's how to configure this:

  • Head to your Azure AD tenant in the Azure Portal, go to Enterprise Applications, find the service's registered app, and open the Permissions tab.
  • Locate the Azure AD Graph application permissions the service has been granted (look for entries like Group.Read.All).
  • Click the ellipsis (...) next to the permission, then select Restrict access.
  • In the restriction panel, choose "Specific groups" and add exactly the groups you want the service to be able to read.
  • Save your changes. From now on, even if the service has a Group.Read.All permission, it will only receive data for the groups you've explicitly allowed.

2. Use a Custom Azure AD Role with Granular Group Scope

If the first method doesn't fit your setup, creating a custom role is another solid option:

  • In the Azure Portal, go to Azure Active Directory > Roles and administrators > New custom role.
  • When defining the role, add the Azure AD Graph permission you need (for example, microsoft.directory/groups/read).
  • Set the Assignable scope to the specific groups you want the service to access—this limits the role's permissions only to those groups.
  • Assign this custom role to the service's application principal (the identity the service uses to authenticate with Azure AD).
  • This ensures the service can only read the groups included in the role's scope, no more.

Important Notes

  • Keep in mind that Azure AD Graph is deprecated. If you can, nudge the service provider to migrate to Microsoft Graph—it offers more granular permission controls and is actively supported.
  • After setting up these restrictions, test them! Use tools like Postman (with the service's credentials) to call the Azure AD Graph groups endpoint and confirm only your allowed groups are returned.

内容的提问来源于stack exchange,提问作者Jay Pete

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 16:57:32