You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Function中PowerShell调用Graph SDK获用户/组遇空引用错误求助

在Azure Function中使用Microsoft Graph PowerShell模块时出现空引用错误

问题详情

我在Azure Function的PowerShell脚本中尝试通过Graph SDK获取用户/组信息,能够成功获取AccessToken并完成Connect-MgGraph连接,但调用Get-MgUser或Get-MgGroup等cmdlet时,始终抛出**"ERROR: Object reference not set to an instance of an object"**错误。相同代码在本地PowerShell窗口中可以正常运行。

复现代码

using namespace System.Net

# Input bindings are passed in via param block.
param($Request, $TriggerMetadata)


$appid = 'eaf7a235'
$tenantid = '723058'
$secret = '~SomeCode'
 
$body =  @{
    Grant_Type    = "client_credentials"
    Scope         = "https://graph.microsoft.com/.default"
    Client_Id     = $appid
    Client_Secret = $secret
}
 
$connection = Invoke-RestMethod `
    -Uri https://login.microsoftonline.com/$tenantid/oauth2/v2.0/token `
    -Method POST `
    -Body $body
 
$token = $connection.access_token  | ConvertTo-SecureString -AsPlainText -Force
 

Connect-MgGraph -AccessToken $token

$user = Get-MgUser -UserId 'someone@here.com' | convertto-json -depth 100 ##here the function crash


Push-OutputBinding -Name Response -Value ([HttpResponseContext]@{
    StatusCode = [HttpStatusCode]::OK
    Body = $user
})

解决方法

这个问题多由Azure Function运行环境与Graph模块的适配性问题导致,可按以下步骤修复:

  • 锁定Graph模块版本
    Azure Function默认安装的模块版本可能与本地不一致,在Function的requirements.psd1中明确指定兼容版本,比如:

    @{
        'Microsoft.Graph.Users' = '2.15.0'
        'Microsoft.Graph.Groups' = '2.15.0'
    }
    
  • 更换认证方式
    手动处理AccessToken的方式在Azure Function环境中易出现上下文丢失,改用服务主体直接认证:

    # 替换原认证代码段
    $authParams = @{
        ClientId     = $appid
        TenantId     = $tenantid
        ClientSecret = ConvertTo-SecureString $secret -AsPlainText -Force
        NoWelcome    = $true
    }
    Connect-MgGraph @authParams
    
  • 验证权限配置
    确认服务主体已在Azure AD中配置User.Read.All(获取用户)或Group.Read.All(获取组)的应用权限,且完成了管理员同意。

  • 捕获详细错误
    添加异常捕获代码,获取更精准的错误堆栈信息:

    try {
        $user = Get-MgUser -UserId 'someone@here.com' | ConvertTo-Json -Depth 100
    }
    catch {
        $errorInfo = $_ | ConvertTo-Json -Depth 100
        Push-OutputBinding -Name Response -Value ([HttpResponseContext]@{
            StatusCode = [HttpStatusCode]::InternalServerError
            Body = $errorInfo
        })
        return
    }
    

内容的提问来源于stack exchange,提问作者user23371259

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 11:41:12