You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

给Service Principal分配SharePoint Administrator角色时提示‘Role assignment is not supported’

问题描述

需要在Microsoft Entra ID中为应用(服务)主体分配SharePoint Administrator角色,以便应用能在SharePoint端写入临时元数据,核心代码示例如下:

web.AllProperties["name"] = "value";
web.Update();
ctx.ExecuteQuery();

执行以下PowerShell脚本时,抛出**“Role assignment is not supported”**错误:

Install-Module Microsoft.Graph.Authentication, Microsoft.Graph.Applications, Microsoft.Graph.Identity.SignIns, Microsoft.Graph.Identity.Governance -Force

Connect-MgGraph -Scopes @(
 "AppRoleAssignment.ReadWrite.All"
 "Application.ReadWrite.All"
 "Directory.ReadWrite.All")

$appId = "my-app-id-comes-here"

$servicePrincipal = Get-MgServicePrincipal -Filter "appId eq '$appId'"

New-MgRoleManagementDirectoryRoleEligibilityScheduleRequest -Action "SelfActivate" -Justification "For writing metadata to SharePoint tenant settings" -DirectoryScopeId "/" -PrincipalId $servicePrincipal.Id -RoleDefinitionId "f28a1f50-f6e7-4571-818b-6a12f2af6b6c" -ScheduleInfo @{
 "StartDateTime" = [System.DateTime]::Now.AddSeconds(10)
 "Expiration" = @{
 "Type" = "NoExpiration"
 }
}

尝试用服务主体的Object ID直接替换$servicePrincipal.Id后,错误变为**“The subject is not found”**。

解决方案

1. 替换错误的动作与Cmdlet

SelfActivate动作仅支持用户自我激活角色资格,服务主体无法使用该方式操作。需改用AdminAssign动作创建角色分配请求,或直接使用New-MgRoleManagementDirectoryRoleAssignment完成直接分配,后者更适合服务主体场景。

修正后的PowerShell脚本

# 安装依赖模块(首次执行需运行)
Install-Module Microsoft.Graph.Authentication, Microsoft.Graph.Identity.Governance -Force

# 连接Microsoft Graph,需使用具备角色分配权限的账号(如全局管理员、特权角色管理员)
Connect-MgGraph -Scopes @(
 "RoleManagement.ReadWrite.Directory"
 "Directory.ReadWrite.All")

$appId = "my-app-id-comes-here"
# 获取目标服务主体
$servicePrincipal = Get-MgServicePrincipal -Filter "appId eq '$appId'"
# SharePoint Administrator角色的固定RoleDefinitionId
$sharePointAdminRoleId = "f28a1f50-f6e7-4571-818b-6a12f2af6b6c"

# 为服务主体分配SharePoint Administrator角色
New-MgRoleManagementDirectoryRoleAssignment `
  -PrincipalId $servicePrincipal.Id `
  -RoleDefinitionId $sharePointAdminRoleId `
  -DirectoryScopeId "/"

2. 解决“The subject is not found”错误

该错误通常由以下原因导致:

  • PrincipalId无效:确认$servicePrincipal.Id返回的是有效服务主体Object ID,可通过Get-MgServicePrincipal -Filter "appId eq '$appId'"检查结果是否存在。
  • 权限不足:连接Graph的账号需具备Directory.Read.All或Directory.ReadWrite.All权限,确保已完成管理员同意。

3. 必要权限说明

执行角色分配操作的账号必须满足以下任一条件:

  • 拥有全局管理员(Global Administrator)角色
  • 拥有特权角色管理员(Privileged Role Administrator)角色
  • 已被授予RoleManagement.ReadWrite.Directory应用权限或委派权限(需管理员同意)

内容的提问来源于stack exchange,提问作者yellow_submarine

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 20:42:08