求Azure PowerShell中配置Delegated Permission的示例代码
使用Azure PowerShell配置应用委托权限(Delegated Permission)示例
前置准备
首先确保已安装Microsoft Graph PowerShell模块,并且拥有足够的权限(比如OAuth2PermissionGrant.ReadWrite.All和Directory.Read.All)来修改权限授予。
完整操作步骤
- 安装并导入Microsoft Graph模块
# 安装模块(首次运行) Install-Module -Name Microsoft.Graph -Force -AllowClobber # 导入身份验证相关模块 Import-Module Microsoft.Graph.Identity.SignIns
- 连接到Microsoft Graph
# 使用所需权限连接,确保账号有目录权限 Connect-MgGraph -Scopes "OAuth2PermissionGrant.ReadWrite.All", "Directory.Read.All"
- 获取必要的ID参数
# 1. 你的客户端应用ID(即需要被授予权限的应用) $clientAppId = "your-client-app-id-here" # 或者通过应用名称获取: # $clientApp = Get-MgApplication -Filter "displayName eq '你的应用显示名称'" # $clientAppId = $clientApp.Id # 2. 目标资源应用ID(以Microsoft Graph为例,固定ID为00000003-0000-0000-c000-000000000000) $resourceAppId = "00000003-0000-0000-c000-000000000000" # 3. 获取要授予的委托权限ID(比如User.Read.All) $resourceServicePrincipal = Get-MgServicePrincipal -Filter "appId eq '$resourceAppId'" $targetPermission = $resourceServicePrincipal.OAuth2PermissionScopes | Where-Object { $_.Value -eq "User.Read.All" } $permissionId = $targetPermission.Id
- 创建委托权限授予
如果需要给所有用户授予该权限(对应“已授予管理员同意”的效果),执行以下命令:
New-MgOAuth2PermissionGrant -ClientId $clientAppId ` -ConsentType "AllPrincipals" ` -ResourceId $resourceServicePrincipal.Id ` -Scope "User.Read.All" ` -ExpiryTime (Get-Date).AddYears(1) ` -StartTime (Get-Date)
如果只需要给特定用户授予权限,将ConsentType改为Principal,并添加PrincipalId参数:
# 替换为目标用户的ID $userId = "target-user-id-here" New-MgOAuth2PermissionGrant -ClientId $clientAppId ` -ConsentType "Principal" ` -PrincipalId $userId ` -ResourceId $resourceServicePrincipal.Id ` -Scope "User.Read.All" ` -ExpiryTime (Get-Date).AddYears(1) ` -StartTime (Get-Date)
验证配置结果
你可以通过以下命令查看已创建的权限授予:
Get-MgOAuth2PermissionGrant -Filter "clientId eq '$clientAppId'"
注意事项
- 确保执行命令的账号拥有全局管理员或应用程序管理员角色,否则会权限不足。
Scope参数可以同时指定多个权限,用空格分隔(比如"User.Read.All Mail.Send")。- 资源应用ID需要根据你实际要访问的服务调整(比如Exchange Online的ID不同)。
内容的提问来源于stack exchange,提问作者Harry
相关产品推荐
相关产品推荐

