You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD中无法创建ClientID-Secret:404错误排查求助

问题

尝试通过client_credentials流在Azure AD中为指定应用生成新的客户端密钥,执行脚本的应用已拥有Application.ReadWrite.All、Application.ReadWrite.OwnedBy及Directory.ReadWrite.All权限(包含应用和委派级别)。

使用的Python代码如下:

import requests
from datetime import datetime, timedelta

# Azure AD B2C Constants
application_id ='888-xxxx-xxxx-xxxxx'
TENANT_ID = 'xxxx-xxxx-xxxxxxx'
CLIENT_ID = 'xxxx-xxxx-xxxxxxx'
CLIENT_SECRET = 'xxxxx-xxxxx-xxxxx'

# Token endpoint to get the access token
token_endpoint = f'https://login.microsoftonline.com/{TENANT_ID}/oauth2/v2.0/token'

# Resource URL
resource_url = 'https://graph.microsoft.com'

# Scopes for the Microsoft Graph API
scopes = ['https://graph.microsoft.com/.default' ]

# Parameters to get the access token
token_data = {
    'grant_type': 'client_credentials',
    'client_id': CLIENT_ID,
    'client_secret': CLIENT_SECRET,
    'scope': ' '.join(scopes)
}

# Get access token
token_response = requests.post(token_endpoint, data=token_data)
access_token = token_response.json().get('access_token')

# Create app registration in Azure AD B2C
create_app_endpoint = f'{resource_url}/v1.0/{TENANT_ID}/applications'
headers = {
    'Authorization': f'Bearer {access_token}',
    'Content-Type': 'application/json'
}

url_password = f'{resource_url}/v1.0/applications/{application_id}/addPassword'

print(url_password)

# Construct the request body with password credentials details
password_credentials_data = {
    "passwordCredential": {
        "displayName": "System_Access_1"
    }
}

# Send the request to create password credentials
response = requests.post(url_password, headers=headers, json=password_credentials_data)

# Check the response
if response.status_code == 200:
    print("Password credentials created successfully.")
else:
    print("Failed to create password credentials. Status code:", response.status_code)
    print("Response:", response.text)

执行后遇到404错误:

https://graph.microsoft.com/v1.0/applications/888-xxxx-xxxx-xxxxx/addPassword

Failed to create password credentials. Status code: 404
Response: {"error":{"code":"Request_ResourceNotFound","message":"Resource '888-xxxx-xxxx-xxxxx' does not exist or one of its queried reference-property objects are not present.","innerError":{"date":"2024-02-26T16:01:36","request-id":" ","client-request-id":""}}}

已确认Azure AD中该应用确实存在,且遵循官方文档步骤操作,询问可能的故障原因。

可能的故障原因

  • 误用客户端ID而非应用对象ID:Graph API的applications/{id}/addPassword端点要求传入的是应用的对象ID,不是应用注册的客户端ID(Client ID)。这两个ID是完全不同的字段,需要到Azure AD应用注册的详情页找到"对象ID"替换application_id变量。
  • 权限配置未生效或类型错误:
    • client_credentials流仅支持应用权限,需确认你配置的权限是应用权限而非委派权限,且已完成管理员同意操作。
    • 检查Application.ReadWrite.All或Application.ReadWrite.OwnedBy权限是否正确授予,是否存在权限策略限制导致无法访问目标应用。
  • 租户ID与应用所在租户不匹配:核实TENANT_ID是否为目标应用实际所在的Azure AD租户ID,若脚本使用的租户和应用所在租户不一致,会导致资源无法被找到。
  • Azure AD缓存延迟:刚创建的应用注册可能存在同步延迟,导致Graph API暂时无法识别该资源,可等待5-10分钟后重试。
  • 应用类型不支持:确认目标应用是标准的Azure AD应用注册,而非B2C用户流、企业应用(仅服务主体)等特殊类型资源,部分特殊应用不支持通过该API添加密钥。

内容的提问来源于stack exchange,提问作者GeekzSG

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 07:53:21