.NET 8环境下ServiceClient SDK获取Power Automate流列表及租户访问问题
.NET 8下获取Power Automate流列表及租户访问配置
一、核心参数获取方法
1. Dataverse环境URL(Url参数)
登录Power Platform管理中心,找到目标环境,在环境详情页复制「环境URL」,格式为https://<环境名称>.crm.dynamics.com
2. 应用程序ID(AppId参数)
- 登录Azure AD主租户(非B2C租户),注册新应用程序
- 在应用概述页复制「客户端ID」,即为AppId
3. 重定向URI(RedirectUri参数)
仅交互式用户认证场景需要,在Azure AD应用的「认证」页面添加重定向URI(如本地测试用https://localhost:5001/signin-oidc);服务端应用采用Client Credentials认证时无需此参数
4. 关于UserName/Password的说明
不推荐使用用户名密码认证,尤其是Azure AD B2C托管的应用。建议采用**Client Credentials(客户端凭据)**方式,更安全且适配服务端应用身份模型,无需用户名密码
二、租户身份访问配置
- 在Azure AD主租户注册的应用,需分配对应权限:
- 进入应用「API权限」页面,添加「Dataverse」应用权限(如
Organization.Read.All)或「Power Automate Management」应用权限(如Flows.Read.All) - 点击「授予管理员同意」完成权限生效
- 进入应用「API权限」页面,添加「Dataverse」应用权限(如
- 确保Azure AD B2C托管应用可访问主租户资源,可通过跨租户应用权限配置实现,或直接在主租户注册应用供B2C应用调用
三、获取流列表的实现代码
方式1:Dataverse ServiceClient(适用于传统工作流)
若需获取Dataverse中的传统工作流,修改为Client Credentials认证方式:
[HttpPost] [Route("test")] public async Task<IActionResult> GetTestData() { string url = "https://your-environment.crm.dynamics.com"; string appId = "your-app-client-id"; string clientSecret = "your-app-client-secret"; string tenantId = "your-tenant-id"; string connectionString = $@" AuthType = OAuth; Url = {url}; ClientId = {appId}; ClientSecret = {clientSecret}; TenantId = {tenantId}; LoginPrompt=Auto; RequireNewInstance = True"; using IOrganizationService service = new ServiceClient(connectionString); // 验证连接有效性 var whoAmI = (WhoAmIResponse)service.Execute(new WhoAmIRequest()); if (whoAmI.UserId == Guid.Empty) { return BadRequest("Dataverse连接失败"); } // 查询传统工作流实体 var query = new QueryExpression("workflow") { ColumnSet = new ColumnSet("name", "workflowid", "type"), Criteria = new FilterExpression { Conditions = { new ConditionExpression("type", ConditionOperator.Equal, 1) } // 1代表工作流类型,可按需调整 } }; var workflows = service.RetrieveMultiple(query).Entities; var flowList = workflows.Select(w => new { Id = w.GetAttributeValue<Guid>("workflowid"), Name = w.GetAttributeValue<string>("name"), Type = w.GetAttributeValue<int>("type") }).ToList(); return Ok(flowList); }
方式2:Power Automate Management API(适用于现代云流)
若需获取现代Power Automate云流,直接调用官方API更适配:
using System.Net.Http.Headers; using System.Text.Json; [HttpPost] [Route("get-flows")] public async Task<IActionResult> GetPowerAutomateFlows() { string tenantId = "your-tenant-id"; string clientId = "your-app-client-id"; string clientSecret = "your-app-client-secret"; string environmentId = "your-power-automate-environment-id"; // Power Platform管理中心环境详情页获取 // 获取访问令牌 var tokenEndpoint = $"https://login.microsoftonline.com/{tenantId}/oauth2/v2.0/token"; using var httpClient = new HttpClient(); var tokenContent = new FormUrlEncodedContent(new Dictionary<string, string> { ["grant_type"] = "client_credentials", ["client_id"] = clientId, ["client_secret"] = clientSecret, ["scope"] = "https://management.azure.com/.default" }); var tokenResponse = await httpClient.PostAsync(tokenEndpoint, tokenContent); tokenResponse.EnsureSuccessStatusCode(); var tokenData = await JsonSerializer.DeserializeAsync<JsonElement>(await tokenResponse.Content.ReadAsStreamAsync()); var accessToken = tokenData.GetProperty("access_token").GetString(); // 调用API获取云流列表 httpClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", accessToken); var flowsEndpoint = $"https://management.azure.com/providers/Microsoft.ProcessSimple/environments/{environmentId}/flows?api-version=2016-11-01"; var flowsResponse = await httpClient.GetAsync(flowsEndpoint); flowsResponse.EnsureSuccessStatusCode(); var flowsData = await flowsResponse.Content.ReadAsStringAsync(); return Ok(flowsData); }
四、注意事项
- 确保应用已被授予足够权限,且管理员完成权限同意操作
- 现代云流必须通过Power Automate Management API获取,Dataverse ServiceClient仅支持传统工作流查询
- Azure AD B2C托管应用访问主租户资源时,需确保跨租户权限配置正确
内容的提问来源于stack exchange,提问作者karan tecmantras
相关产品推荐
相关产品推荐

