You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure应用调用Microsoft Graph API访问共享文件夹遇403权限拒绝

访问公开共享OneDrive文件夹时的403权限拒绝问题解决

问题现象

调用Microsoft Graph API访问公开共享的OneDrive文件夹时返回403错误:

Fatal error: Uncaught GuzzleHttp\Exception\ClientException: Client error: 
`GET https://graph.microsoft.com/v1.0/shares/u!aHR0cHM6Ly8xZHJ2Lm1zL2Yvcy
FBdHVBTV9OYWN3VmFoaUZwdU1HU19CaVFDd1d1/root?expand=children` resulted in a 
`403 Forbidden` response: 

{"error":{"code":"accessDenied","message":"The 
    sharing link no longer exists, or you do not have permission to access 
    it."

,"innerError":{"date":"2023-10-11T05:01:49","request-id":"27bd1fc1-
74f8-4d8d-9a43-41a3aa6a9f02","client-request-id":"27bd1fc1-74f8-4d8d-9a43
-41a3aa6a9f02"}}}

该共享链接在浏览器中可正常访问,但应用调用时被拒绝。当前应用的Access Token已包含以下权限:

{
  "appid": "563e2470-8b86-48dc-9050-20228336584e",
  "appidacr": "1",
  "idp": "https://sts.windows.net/74162350-5947-4628-892f-4ee1d28d88cc/",
  "idtyp": "app",
  "oid": "d9b6b299-ddc2-4708-ac87-2a48beb896f4",
  "rh": "0.AUIAUCMWdEdZKEaJL07h0o2IzAMAAAAAAAAAwAAAAAAAAACkAAA.",
  "roles": [
    "Application.ReadWrite.All",
    "Sites.Read.All",
    "Application.Read.All"
  ],
  "sub": "d9b6b299-ddc2-4708-ac87-2a48beb896f4",
  "tenant_region_scope": "OC",
  "tid": "74162350-5947-4628-892f-4ee1d28d88cc",
  "uti": "rJQ_ra77J0ux9XBeCvMIAA",
  "ver": "1.0",
  "wids": [
    "0997a1d0-0d1d-4acb-b408-d5ca73121e90"
  ]
}

调用代码片段(在->execute()处失败):

$guzzle = new \GuzzleHttp\Client();
$url = 'https://login.microsoftonline.com/' . $tenantId . '/oauth2/v2.0/token';
/*
* If the client requests scope=https://graph.microsoft.com/.default, no consent prompt is shown, regardless of the contents of the client application's registered permissions for Microsoft Graph. The returned token contains the scopes Mail.Read and User.Read.
*/
$token = json_decode($guzzle->post($url, [
    'form_params' => [
    'client_id' => $clientId,
    'scope' => 'https://graph.microsoft.com/.default',
    'grant_type' => 'client_credentials',
    'client_secret' => $clientSecret,
    ],
])->getBody()->getContents());
$accessToken = $token->access_token;

$graph = new Graph();
$graph->setAccessToken($accessToken);
$user = $graph->createRequest("GET", "/shares/u!aHR0cHM6Ly8xZHJ2Lm1zL2YvcyFBdHVBTV9OYWN3VmFoaUZwdU1HU19CaVFDd1d1/root?expand=children")
       ->setReturnType(Microsoft\Graph\Model\DriveItem::class)
       ->execute();

问题分析与解决方法

  1. 核心权限缺失:当前应用权限列表中缺少Files.Read.All应用权限。Sites.Read.All仅针对SharePoint站点内容,访问OneDrive共享文件/文件夹需要专门的文件权限。客户端凭据模式下必须添加Files.Read.All应用权限并完成管理员同意。
  2. 共享链接权限限制:确认共享链接是"任何人可访问"类型,若为"仅限组织内部",客户端凭据模式下的应用无法跨租户访问该资源。需调整共享链接权限为完全公开,或确保应用与共享资源属于同一租户。
  3. API调用验证:重新获取Access Token后,检查token的roles字段是否包含Files.Read.All,确认权限已生效后再发起API请求。

操作步骤

  • 登录Azure门户,进入目标应用注册页面,选择"API权限"选项卡。
  • 点击"添加权限",选择"Microsoft Graph",再选择"应用权限",搜索并添加Files.Read.All权限。
  • 点击"授予管理员同意",确保权限生效。
  • 重新运行代码获取新的Access Token,再次调用Graph API。

内容的提问来源于stack exchange,提问作者Alexander

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 15:38:09