Azure AD中无法创建ClientID-Secret:404错误排查求助
问题
尝试通过client_credentials流在Azure AD中为指定应用生成新的客户端密钥,执行脚本的应用已拥有Application.ReadWrite.All、Application.ReadWrite.OwnedBy及Directory.ReadWrite.All权限(包含应用和委派级别)。
使用的Python代码如下:
import requests from datetime import datetime, timedelta # Azure AD B2C Constants application_id ='888-xxxx-xxxx-xxxxx' TENANT_ID = 'xxxx-xxxx-xxxxxxx' CLIENT_ID = 'xxxx-xxxx-xxxxxxx' CLIENT_SECRET = 'xxxxx-xxxxx-xxxxx' # Token endpoint to get the access token token_endpoint = f'https://login.microsoftonline.com/{TENANT_ID}/oauth2/v2.0/token' # Resource URL resource_url = 'https://graph.microsoft.com' # Scopes for the Microsoft Graph API scopes = ['https://graph.microsoft.com/.default' ] # Parameters to get the access token token_data = { 'grant_type': 'client_credentials', 'client_id': CLIENT_ID, 'client_secret': CLIENT_SECRET, 'scope': ' '.join(scopes) } # Get access token token_response = requests.post(token_endpoint, data=token_data) access_token = token_response.json().get('access_token') # Create app registration in Azure AD B2C create_app_endpoint = f'{resource_url}/v1.0/{TENANT_ID}/applications' headers = { 'Authorization': f'Bearer {access_token}', 'Content-Type': 'application/json' } url_password = f'{resource_url}/v1.0/applications/{application_id}/addPassword' print(url_password) # Construct the request body with password credentials details password_credentials_data = { "passwordCredential": { "displayName": "System_Access_1" } } # Send the request to create password credentials response = requests.post(url_password, headers=headers, json=password_credentials_data) # Check the response if response.status_code == 200: print("Password credentials created successfully.") else: print("Failed to create password credentials. Status code:", response.status_code) print("Response:", response.text)
执行后遇到404错误:
https://graph.microsoft.com/v1.0/applications/888-xxxx-xxxx-xxxxx/addPassword Failed to create password credentials. Status code: 404 Response: {"error":{"code":"Request_ResourceNotFound","message":"Resource '888-xxxx-xxxx-xxxxx' does not exist or one of its queried reference-property objects are not present.","innerError":{"date":"2024-02-26T16:01:36","request-id":" ","client-request-id":""}}}
已确认Azure AD中该应用确实存在,且遵循官方文档步骤操作,询问可能的故障原因。
可能的故障原因
- 误用客户端ID而非应用对象ID:Graph API的
applications/{id}/addPassword端点要求传入的是应用的对象ID,不是应用注册的客户端ID(Client ID)。这两个ID是完全不同的字段,需要到Azure AD应用注册的详情页找到"对象ID"替换application_id变量。 - 权限配置未生效或类型错误:
client_credentials流仅支持应用权限,需确认你配置的权限是应用权限而非委派权限,且已完成管理员同意操作。- 检查
Application.ReadWrite.All或Application.ReadWrite.OwnedBy权限是否正确授予,是否存在权限策略限制导致无法访问目标应用。
- 租户ID与应用所在租户不匹配:核实
TENANT_ID是否为目标应用实际所在的Azure AD租户ID,若脚本使用的租户和应用所在租户不一致,会导致资源无法被找到。 - Azure AD缓存延迟:刚创建的应用注册可能存在同步延迟,导致Graph API暂时无法识别该资源,可等待5-10分钟后重试。
- 应用类型不支持:确认目标应用是标准的Azure AD应用注册,而非B2C用户流、企业应用(仅服务主体)等特殊类型资源,部分特殊应用不支持通过该API添加密钥。
内容的提问来源于stack exchange,提问作者GeekzSG
相关产品推荐
相关产品推荐

