拥有Directory.ReadWrite.All权限却无法调用Get-MgUser的问题求助
权限不足问题排查:使用Directory.ReadWrite.All权限调用Microsoft Graph cmdlets失败
问题背景
我们在合作伙伴租户中发布了一个应用,已授予Directory.ReadWrite.All权限(包含委派权限和应用权限),并将该应用推送给所有客户租户,配置了相同权限及其他相关权限。我们通过New-PartnerAccessToken生成访问令牌,再借助该令牌通过Connect-MgGraph连接到客户租户,以运行Mg cmdlets。
最初在测试应用中使用Directory.AccessAsUser.All权限时,此方法运行一切正常,所有所需Mg cmdlets都能正常执行。但切换为Directory.ReadWrite.All(或User.ReadWrite.All等更低权限)时,所有cmdlets均返回权限不足错误,尽管Directory.ReadWrite.All权限本应支持大量cmdlets。
我们与所有客户租户均建立了活跃的GDAP关系,配置了必要角色,且所在管理员代理组已加入该关系并被授予所有角色。无法理解为何已拥有包含directory.readwrite.all范围的活跃MgGraph会话,却无法运行Get-MgUser。
相关代码片段
$AppCredential = (New-Object System.Management.Automation.PSCredential ($AppId, ($AppSecret))) $PartnerAccessToken = New-PartnerAccessToken -serviceprincipal -ApplicationId $AppId -Credential $AppCredential -Scopes $consentscope -tenant $PartnerTenantid -UseAuthorizationCode Connect-PartnerCenter -AccessToken $PartnerAccessToken.AccessToken $GraphToken = ConvertTo-SecureString (New-PartnerAccessToken -ApplicationId $AppId -Credential $appcredential -RefreshToken $PartnerAccesstoken.refreshToken -Scopes 'https://graph.microsoft.com/.default' -Tenant $CustomerTenantId).AccessToken -AsPlainText -Force Connect-MgGraph -AccessToken $graphToken
补充参考信息
始终未查明具体原因,最终通过Graph API删除应用并重新发布,改用Directory.AccessAsUser.All权限后问题解决。
相关截图
- 应用权限截图:

- MgContext及错误截图:

内容的提问来源于stack exchange,提问作者phoneybaloneypshell
相关产品推荐
相关产品推荐

