You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Partner Center PowerShell脚本New-PartnerCustomerApplicationConsent错误排查

特定租户下Partner Center应用同意脚本执行失败问题

我使用PowerShell脚本通过Partner Center API自动创建应用同意,该脚本在数百个多租户环境中均可成功运行,但针对某一特定租户出现异常:

  1. 初始报错为AADSTS53003:访问被条件访问策略阻止
  2. 禁用相关条件访问策略后,又抛出Providers.Common.V1.CoreException异常

脚本内容

# Define the consent scope
$consentscope = 'https://api.partnercenter.microsoft.com/user_impersonation'

# Create a PSCredential object with the provided values
$AppCredential = New-Object System.Management.Automation.PSCredential ($AppId, (ConvertTo-SecureString $AppSecret -AsPlainText -Force))

# Get PartnerAccessToken token
$PartnerAccessToken = New-PartnerAccessToken -serviceprincipal -ApplicationId $AppId -Credential $AppCredential -Scopes $consentscope -tenant $PartnerTenantid -UseAuthorizationCode

# Connect to PartnerCenter with the AccessToken
$PartnerCenter = Connect-PartnerCenter -AccessToken $PartnerAccessToken.AccessToken

# Define the customer TenantID
$CustomerTenantId = "sample ID"

# Define the application grants with expanded scopes
$MSGraphgrant = New-Object -TypeName Microsoft.Store.PartnerCenter.Models.ApplicationConsents.ApplicationGrant
$MSGraphgrant.EnterpriseApplicationId = "00000003-0000-0000-c000-000000000000"
$MSGraphgrant.Scope = "User.ReadWrite.All, Directory.ReadWrite.All, License.ReadWrite.All"

$ExOgrant = New-Object -TypeName Microsoft.Store.PartnerCenter.Models.ApplicationConsents.ApplicationGrant
$ExOgrant.EnterpriseApplicationId = "00000002-0000-0ff1-ce00-000000000000"
$ExOgrant.Scope = "Exchange.Manage"

# Create a new consent for the customer
New-PartnerCustomerApplicationConsent -ApplicationGrants @($MSGraphgrant, $ExOgrant) -CustomerId $CustomerTenantId -ApplicationId $AppId -DisplayName $AppDisplayName

错误详情

初始错误(条件访问阻止)

{
"type": "MsalUiRequiredException",
"error_code": "invalid_grant",
"error_description": "AADSTS53003: Access has been blocked by Conditional Access policies. The access policy does not allow token issuance. Trace ID: 810e03f7-3a6b-462a-a3ea-6d7e2dbaac00 Correlation ID: aec144b1-92d1-421e-9880-e77c4516fee6 Timestamp: 2024-01-17 08:44:52Z",
"claims": "{"access_token":{"capolids":{"essential":true,"values":["b9331cd7-cd9d-40a8-84bb-652b51608815"]}}}",
"response_body": "{"error":"invalid_grant","error_description":"AADSTS53003: Access has been blocked by Conditional Access policies. The access policy does not allow token issuance. Trace ID: 810e03f7-3a6b-462a-a3ea-6d7e2dbaac00 Correlation ID: aec144b1-92d1-421e-9880-e77c4516fee6 Timestamp: 2024-01-17 08:44:52Z","error_codes":[53003],"timestamp":"2024-01-17 08:44:52Z","trace_id":"810e03f7-3a6b-462a-a3ea-6d7e2dbaac00","correlation_id":"aec144b1-92d1-421e-9880-e77c4516fee6","error_uri":"https://login.microsoftonline.com/error?code=53003","suberror":"message_only","claims":"{\"access_token\":{\"capolids\":{\"essential\":true,\"values\":[\"b9331cd7-cd9d-40a8-84bb-652b51608815\"]}}}"}",
"correlation_id": "aec144b1-92d1-421e-9880-e77c4516fee6",
"sub_error": "message_only"
}

禁用条件访问后的错误

New-PartnerCustomerApplicationConsent : Exception of type 'Providers.Common.V1.CoreException' was thrown.
At C:\Users\benp_support\OneDrive - Allegronet\Desktop\ExportAllLicenses\Consent_New_Tenant.ps1:32 char:1
- New-PartnerCustomerApplicationConsent -ApplicationGrants @($MSGraphgr ...
-
  + CategoryInfo          : CloseError: (:) [New-PartnerCustomerApplicationConsent], PartnerException
  + FullyQualifiedErrorId : Microsoft.Store.PartnerCenter.PowerShell.Commands.NewPartnerCustomerApplicationConsent

解决方案

1. 验证GDAP权限配置

  • 确认该特定租户的**细粒度委派管理员权限(GDAP)**已正确配置,需包含脚本中请求的所有权限:
    • Microsoft Graph:User.ReadWrite.All、Directory.ReadWrite.All、License.ReadWrite.All
    • Exchange Online:Exchange.Manage
  • GDAP权限生效可能需要数小时,需确认权限已完成同步

2. 检查应用注册与代理权限

  • 确认你的服务主体应用注册已在Partner Center中获得该租户的代理访问权限,且未被租户管理员手动限制
  • 检查该租户是否存在应用权限的拒绝记录(Azure AD > 企业应用 > 权限 > 审核日志)

3. 排查租户安全配置

  • 检查租户是否启用管理员同意限制(Azure AD > 企业应用 > 同意和权限 > 用户同意设置),确保允许通过API授予管理员级权限
  • 验证租户是否启用了安全默认值或其他特殊安全策略,这类策略可能阻止服务主体的权限授予操作

4. 修正脚本认证流程

服务主体认证无需使用授权码流程,修改New-PartnerAccessToken命令:

$PartnerAccessToken = New-PartnerAccessToken -ServicePrincipal -ApplicationId $AppId -Credential $AppCredential -Scopes $consentscope -Tenant $PartnerTenantid

移除-UseAuthorizationCode参数,避免触发交互式认证逻辑

5. 手动测试权限授予

  • 尝试通过Partner Center门户手动为该租户授予应用权限,验证是否能成功
  • 如果手动操作也失败,联系该租户管理员确认是否存在内部权限限制或合规政策

内容的提问来源于stack exchange,提问作者Chess_Shark

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 04:54:52