使用Python调用Graph API查询Azure AD用户/组时权限不足问题
解决Azure应用调用Graph API权限不足问题
问题重现
使用以下Python代码调用Azure AD Graph API(注:使用的是azure.graphrbac库,对应旧版Azure AD Graph而非Microsoft Graph)时,遍历用户和组列表触发权限错误:
from azure.common.credentials import ServicePrincipalCredentials from azure.graphrbac import GraphRbacManagementClient credentials = ServicePrincipalCredentials( client_id="my_id", secret="my_secret", resource="https://graph.windows.net", tenant = 'my_tenant' ) tenant_id = 'my_tenant_id' graphrbac_client = GraphRbacManagementClient(credentials,tenant_id) users = graphrbac_client.users.list() print(users) for user in users: # permissions error here print(user.user_principal_name) groups = graphrbac_client.groups.list() print(groups) for g in groups: # permissions error here print(g.display_name)
错误信息:
azure_ad_testing.py", line 16, in <module> for user in users: azure.graphrbac.models.graph_error.GraphErrorException: Insufficient privileges to complete the operation. line 21, in <module> for g in groups: azure.graphrbac.models.graph_error.GraphErrorException: Insufficient privileges to complete the operation.
权限配置解决方案
你需要为Azure应用添加Azure AD Graph的应用权限,并完成管理员同意:
- 读取用户列表:添加
Directory.Read.All(应用权限,非委派权限) - 读取组列表:添加
Directory.Read.All或Group.Read.All(应用权限,非委派权限)
关键注意点:
- 必须选择应用权限,服务主体(Service Principal)调用接口时不使用委派权限
- 添加权限后,必须点击授予管理员同意按钮,否则配置的权限不会生效
内容的提问来源于stack exchange,提问作者BLang
相关产品推荐
相关产品推荐

