You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Net6 Azure App Service带AAD权限接口的定时调用认证方案咨询

解决方案:服务对服务调用AAD认证的Web App接口

因为直接调用接口时未携带AAD身份凭证,所以会被重定向到登录页。针对定时任务这类无用户交互的场景,推荐使用**客户端凭证流(Client Credentials Flow)**实现服务对服务的认证,以下提供两种实现方式:


一、控制台程序(WebJob)实现步骤

  1. 前置配置

    • 在Web App对应的应用注册中,确认已定义Root应用角色。
    • 创建或使用现有应用注册作为WebJob的服务主体,在Azure企业应用中,给该服务主体分配Web App的Root角色。
    • 记录以下信息:租户ID、WebJob应用注册的客户端ID、客户端密钥、Web App应用注册的Application ID URI(API标识符)。
  2. 修改控制台代码
    替换原有代码,先获取AAD令牌再调用接口:

using System.Net.Http.Headers;
using System.Text.Json;

// 替换为你的实际配置
var tenantId = "你的租户ID";
var clientId = "WebJob应用注册的客户端ID";
var clientSecret = "WebJob应用注册的客户端密钥";
var apiScope = "WebApp应用注册的Application ID URI/.default"; // 示例:https://contoso.onmicrosoft.com/mywebapp/.default
var apiUrl = "https://xxx.azurewebsites.net/cont/act";

// 获取AAD访问令牌
var tokenEndpoint = $"https://login.microsoftonline.com/{tenantId}/oauth2/v2.0/token";
var tokenRequest = new FormUrlEncodedContent(new[]
{
    new KeyValuePair<string, string>("grant_type", "client_credentials"),
    new KeyValuePair<string, string>("client_id", clientId),
    new KeyValuePair<string, string>("client_secret", clientSecret),
    new KeyValuePair<string, string>("scope", apiScope)
});

using var httpClient = new HttpClient();
var tokenResponse = await httpClient.PostAsync(tokenEndpoint, tokenRequest);
tokenResponse.EnsureSuccessStatusCode();
var tokenContent = await tokenResponse.Content.ReadAsStringAsync();
var tokenData = JsonSerializer.Deserialize<JsonElement>(tokenContent);
var accessToken = tokenData.GetProperty("access_token").GetString();

// 携带令牌调用受保护接口
httpClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", accessToken);
var apiResponse = await httpClient.GetAsync(apiUrl);
apiResponse.EnsureSuccessStatusCode();
var apiContent = await apiResponse.Content.ReadAsStringAsync();
Console.WriteLine(apiContent);

二、PowerShell实现步骤

  1. 前置配置
    同控制台程序的前置配置,准备好租户ID、客户端ID、客户端密钥、Web App的API标识符。

  2. PowerShell脚本示例

# 替换为你的实际配置
$tenantId = "你的租户ID"
$clientId = "WebJob应用注册的客户端ID"
$clientSecret = "WebJob应用注册的客户端密钥"
$apiScope = "WebApp应用注册的Application ID URI/.default"
$apiUrl = "https://xxx.azurewebsites.net/cont/act"

# 获取访问令牌
$tokenBody = @{
    Grant_Type    = "client_credentials"
    Scope         = $apiScope
    Client_Id     = $clientId
    Client_Secret = $clientSecret
}
$tokenResponse = Invoke-RestMethod -Uri "https://login.microsoftonline.com/$tenantId/oauth2/v2.0/token" -Method POST -Body $tokenBody
$accessToken = $tokenResponse.access_token

# 调用接口
$headers = @{
    "Authorization" = "Bearer $accessToken"
}
$apiResponse = Invoke-RestMethod -Uri $apiUrl -Method Get -Headers $headers
Write-Output $apiResponse

注意事项

  • 客户端密钥避免硬编码,建议存入Azure密钥保管库,通过托管身份让WebJob或PowerShell脚本安全获取。
  • 应用角色分配后可能需要1-5分钟生效,若出现403权限不足错误,可等待片刻后重试。

内容的提问来源于stack exchange,提问作者Zdenek Barta

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 12:47:01