You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用Graph API获取M365登录活动提示用户角色不允许的问题咨询

咨询:获取Microsoft Entra ID登录活动(signinactivity)数据所需的用户角色

我们需要为部分客户获取显示名称与signinactivity(登录活动)数据,当前使用Microsoft Entra ID Premium环境,通过Graph API Explorer测试获取登录活动数据时,已申请AuditLog.Read.All和Directory.Read.All权限,但遇到以下错误:

"error": {
    "code": "Authentication_RequestFromUnsupportedUserRole",
    "message": "User is not in the allowed roles",
}

当前获取到的Token权限范围(scp)如下:

"scp": "APIConnectors.Read.All AuditLog.Read.All Directory.Read.All Directory.ReadWrite.All OnlineMeetingArtifact.Read.All OnlineMeetings.Read openid profile User.Read User.Read.All User.ReadBasic.All User.ReadWrite User.ReadWrite.All email"

相关角色与权限信息:

  • 用户当前角色:全局读取者、报告读取者、目录读取者
  • 已配置的应用权限:AuditLog.Read.All(已授予)、Directory.Read.All(已授予)等

请问获取signinactivity数据需要用户拥有哪些角色?

内容的提问来源于stack exchange,提问作者Tim Whatley

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 00:43:22