You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求Azure PowerShell中配置Delegated Permission的示例代码

使用Azure PowerShell配置应用委托权限(Delegated Permission)示例

前置准备

首先确保已安装Microsoft Graph PowerShell模块,并且拥有足够的权限(比如OAuth2PermissionGrant.ReadWrite.All和Directory.Read.All)来修改权限授予。

完整操作步骤

  1. 安装并导入Microsoft Graph模块
# 安装模块(首次运行)
Install-Module -Name Microsoft.Graph -Force -AllowClobber

# 导入身份验证相关模块
Import-Module Microsoft.Graph.Identity.SignIns
  1. 连接到Microsoft Graph
# 使用所需权限连接,确保账号有目录权限
Connect-MgGraph -Scopes "OAuth2PermissionGrant.ReadWrite.All", "Directory.Read.All"
  1. 获取必要的ID参数
# 1. 你的客户端应用ID(即需要被授予权限的应用)
$clientAppId = "your-client-app-id-here"
# 或者通过应用名称获取:
# $clientApp = Get-MgApplication -Filter "displayName eq '你的应用显示名称'"
# $clientAppId = $clientApp.Id

# 2. 目标资源应用ID(以Microsoft Graph为例,固定ID为00000003-0000-0000-c000-000000000000)
$resourceAppId = "00000003-0000-0000-c000-000000000000"

# 3. 获取要授予的委托权限ID(比如User.Read.All)
$resourceServicePrincipal = Get-MgServicePrincipal -Filter "appId eq '$resourceAppId'"
$targetPermission = $resourceServicePrincipal.OAuth2PermissionScopes | Where-Object { $_.Value -eq "User.Read.All" }
$permissionId = $targetPermission.Id
  1. 创建委托权限授予
    如果需要给所有用户授予该权限(对应“已授予管理员同意”的效果),执行以下命令:
New-MgOAuth2PermissionGrant -ClientId $clientAppId `
                             -ConsentType "AllPrincipals" `
                             -ResourceId $resourceServicePrincipal.Id `
                             -Scope "User.Read.All" `
                             -ExpiryTime (Get-Date).AddYears(1) `
                             -StartTime (Get-Date)

如果只需要给特定用户授予权限,将ConsentType改为Principal,并添加PrincipalId参数:

# 替换为目标用户的ID
$userId = "target-user-id-here"

New-MgOAuth2PermissionGrant -ClientId $clientAppId `
                             -ConsentType "Principal" `
                             -PrincipalId $userId `
                             -ResourceId $resourceServicePrincipal.Id `
                             -Scope "User.Read.All" `
                             -ExpiryTime (Get-Date).AddYears(1) `
                             -StartTime (Get-Date)

验证配置结果

你可以通过以下命令查看已创建的权限授予:

Get-MgOAuth2PermissionGrant -Filter "clientId eq '$clientAppId'"

注意事项

  • 确保执行命令的账号拥有全局管理员或应用程序管理员角色,否则会权限不足。
  • Scope参数可以同时指定多个权限,用空格分隔(比如"User.Read.All Mail.Send")。
  • 资源应用ID需要根据你实际要访问的服务调整(比如Exchange Online的ID不同)。

内容的提问来源于stack exchange,提问作者Harry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 23:35:11