Azure Partner Center PowerShell脚本New-PartnerCustomerApplicationConsent错误排查
特定租户下Partner Center应用同意脚本执行失败问题
我使用PowerShell脚本通过Partner Center API自动创建应用同意,该脚本在数百个多租户环境中均可成功运行,但针对某一特定租户出现异常:
- 初始报错为AADSTS53003:访问被条件访问策略阻止
- 禁用相关条件访问策略后,又抛出
Providers.Common.V1.CoreException异常
脚本内容
# Define the consent scope $consentscope = 'https://api.partnercenter.microsoft.com/user_impersonation' # Create a PSCredential object with the provided values $AppCredential = New-Object System.Management.Automation.PSCredential ($AppId, (ConvertTo-SecureString $AppSecret -AsPlainText -Force)) # Get PartnerAccessToken token $PartnerAccessToken = New-PartnerAccessToken -serviceprincipal -ApplicationId $AppId -Credential $AppCredential -Scopes $consentscope -tenant $PartnerTenantid -UseAuthorizationCode # Connect to PartnerCenter with the AccessToken $PartnerCenter = Connect-PartnerCenter -AccessToken $PartnerAccessToken.AccessToken # Define the customer TenantID $CustomerTenantId = "sample ID" # Define the application grants with expanded scopes $MSGraphgrant = New-Object -TypeName Microsoft.Store.PartnerCenter.Models.ApplicationConsents.ApplicationGrant $MSGraphgrant.EnterpriseApplicationId = "00000003-0000-0000-c000-000000000000" $MSGraphgrant.Scope = "User.ReadWrite.All, Directory.ReadWrite.All, License.ReadWrite.All" $ExOgrant = New-Object -TypeName Microsoft.Store.PartnerCenter.Models.ApplicationConsents.ApplicationGrant $ExOgrant.EnterpriseApplicationId = "00000002-0000-0ff1-ce00-000000000000" $ExOgrant.Scope = "Exchange.Manage" # Create a new consent for the customer New-PartnerCustomerApplicationConsent -ApplicationGrants @($MSGraphgrant, $ExOgrant) -CustomerId $CustomerTenantId -ApplicationId $AppId -DisplayName $AppDisplayName
错误详情
初始错误(条件访问阻止)
{ "type": "MsalUiRequiredException", "error_code": "invalid_grant", "error_description": "AADSTS53003: Access has been blocked by Conditional Access policies. The access policy does not allow token issuance. Trace ID: 810e03f7-3a6b-462a-a3ea-6d7e2dbaac00 Correlation ID: aec144b1-92d1-421e-9880-e77c4516fee6 Timestamp: 2024-01-17 08:44:52Z", "claims": "{"access_token":{"capolids":{"essential":true,"values":["b9331cd7-cd9d-40a8-84bb-652b51608815"]}}}", "response_body": "{"error":"invalid_grant","error_description":"AADSTS53003: Access has been blocked by Conditional Access policies. The access policy does not allow token issuance. Trace ID: 810e03f7-3a6b-462a-a3ea-6d7e2dbaac00 Correlation ID: aec144b1-92d1-421e-9880-e77c4516fee6 Timestamp: 2024-01-17 08:44:52Z","error_codes":[53003],"timestamp":"2024-01-17 08:44:52Z","trace_id":"810e03f7-3a6b-462a-a3ea-6d7e2dbaac00","correlation_id":"aec144b1-92d1-421e-9880-e77c4516fee6","error_uri":"https://login.microsoftonline.com/error?code=53003","suberror":"message_only","claims":"{\"access_token\":{\"capolids\":{\"essential\":true,\"values\":[\"b9331cd7-cd9d-40a8-84bb-652b51608815\"]}}}"}", "correlation_id": "aec144b1-92d1-421e-9880-e77c4516fee6", "sub_error": "message_only" }
禁用条件访问后的错误
New-PartnerCustomerApplicationConsent : Exception of type 'Providers.Common.V1.CoreException' was thrown. At C:\Users\benp_support\OneDrive - Allegronet\Desktop\ExportAllLicenses\Consent_New_Tenant.ps1:32 char:1 - New-PartnerCustomerApplicationConsent -ApplicationGrants @($MSGraphgr ... - + CategoryInfo : CloseError: (:) [New-PartnerCustomerApplicationConsent], PartnerException + FullyQualifiedErrorId : Microsoft.Store.PartnerCenter.PowerShell.Commands.NewPartnerCustomerApplicationConsent
解决方案
1. 验证GDAP权限配置
- 确认该特定租户的**细粒度委派管理员权限(GDAP)**已正确配置,需包含脚本中请求的所有权限:
- Microsoft Graph:
User.ReadWrite.All、Directory.ReadWrite.All、License.ReadWrite.All - Exchange Online:
Exchange.Manage
- Microsoft Graph:
- GDAP权限生效可能需要数小时,需确认权限已完成同步
2. 检查应用注册与代理权限
- 确认你的服务主体应用注册已在Partner Center中获得该租户的代理访问权限,且未被租户管理员手动限制
- 检查该租户是否存在应用权限的拒绝记录(Azure AD > 企业应用 > 权限 > 审核日志)
3. 排查租户安全配置
- 检查租户是否启用管理员同意限制(Azure AD > 企业应用 > 同意和权限 > 用户同意设置),确保允许通过API授予管理员级权限
- 验证租户是否启用了安全默认值或其他特殊安全策略,这类策略可能阻止服务主体的权限授予操作
4. 修正脚本认证流程
服务主体认证无需使用授权码流程,修改New-PartnerAccessToken命令:
$PartnerAccessToken = New-PartnerAccessToken -ServicePrincipal -ApplicationId $AppId -Credential $AppCredential -Scopes $consentscope -Tenant $PartnerTenantid
移除-UseAuthorizationCode参数,避免触发交互式认证逻辑
5. 手动测试权限授予
- 尝试通过Partner Center门户手动为该租户授予应用权限,验证是否能成功
- 如果手动操作也失败,联系该租户管理员确认是否存在内部权限限制或合规政策
内容的提问来源于stack exchange,提问作者Chess_Shark
相关产品推荐
相关产品推荐

