You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Python调用Graph API查询Azure AD用户/组时权限不足问题

解决Azure应用调用Graph API权限不足问题

问题重现

使用以下Python代码调用Azure AD Graph API(注:使用的是azure.graphrbac库,对应旧版Azure AD Graph而非Microsoft Graph)时,遍历用户和组列表触发权限错误:

from azure.common.credentials import ServicePrincipalCredentials
from azure.graphrbac import GraphRbacManagementClient

credentials = ServicePrincipalCredentials(
    client_id="my_id",
    secret="my_secret",
    resource="https://graph.windows.net",
    tenant = 'my_tenant'
)
tenant_id = 'my_tenant_id'
graphrbac_client = GraphRbacManagementClient(credentials,tenant_id)


users = graphrbac_client.users.list()
print(users)
for user in users:           # permissions error here
     print(user.user_principal_name)

groups = graphrbac_client.groups.list()
print(groups)
for g in groups:           # permissions error here
     print(g.display_name)

错误信息:

azure_ad_testing.py", line 16, in <module>
    for user in users:
azure.graphrbac.models.graph_error.GraphErrorException: Insufficient privileges to complete the operation.
line 21, in <module>
    for g in groups:
azure.graphrbac.models.graph_error.GraphErrorException: Insufficient privileges to complete the operation.

权限配置解决方案

你需要为Azure应用添加Azure AD Graph的应用权限,并完成管理员同意:

  • 读取用户列表:添加Directory.Read.All(应用权限,非委派权限)
  • 读取组列表:添加Directory.Read.All或Group.Read.All(应用权限,非委派权限)

关键注意点:

  • 必须选择应用权限,服务主体(Service Principal)调用接口时不使用委派权限
  • 添加权限后,必须点击授予管理员同意按钮,否则配置的权限不会生效

内容的提问来源于stack exchange,提问作者BLang

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 17:03:21