You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Microsoft Graph获取SharePoint Online应用角色内部ID

获取SharePoint Online应用角色租户专属内部ID的方法

问题背景

需要获取SharePoint Online对应应用角色的租户专属内部ID(对应截图中的第二项),用于在自助工具中授予管理员权限。

此前尝试通过Microsoft Graph查询相关信息:

  • 查询Microsoft Graph服务主体时,能正常返回包含角色ID的结果:
    GET https://graph.microsoft.com/v1.0/servicePrincipals?$filter=displayName eq 'Microsoft Graph'&$select=displayName,appRoles
    
    返回的角色示例:
    {
        "allowedMemberTypes": [
            "Application"
        ],
        "description": "Allow the application to access a subset of site collections without a signed in user.  The specific site collections and the permissions granted will be configured in SharePoint Online.",
        "displayName": "Access selected site collections",
        "id": "....",
        "isEnabled": true,
        "origin": "Application",
        "value": "Sites.Selected"
    }
    
  • 但查询所有名称以SharePoint开头的服务主体时,返回结果的appRoles数组全为空:
    GET https://graph.microsoft.com/v1.0/servicePrincipals?$filter=startswith(displayName,'SharePoint')&$select=displayName,appRoles
    
    返回示例:
    {
        "@odata.context": "https://graph.microsoft.com/v1.0/$metadata#servicePrincipals(displayName,appRoles)",
        "value": [
            {
                "displayName": "SharePoint Home Notifier",
                "appRoles": []
            },
            {
                "displayName": "SharePoint Notification Service",
                "appRoles": []
            },
            {
                "displayName": "SharePoint Notification Service",
                "appRoles": []
            },
            {
                "displayName": "SharePoint Online Client",
                "appRoles": []
            },
            {
                "displayName": "SharePoint Online Client Extensibility",
                "appRoles": []
            },
            {
                "displayName": "SharePoint Online Client Extensibility Web Application Principal",
                "appRoles": []
            },
            {
                "displayName": "SharePoint Online Client Extensibility Web Application Principal Helper",
                "appRoles": []
            },
            {
                "displayName": "SharePoint Online Web Client Extensibility",
                "appRoles": []
            },
            {
                "displayName": "SharePoint Online Web Client Extensibility Isolated",
                "appRoles": []
            },
            {
                "displayName": "SharePointAdmin",
                "appRoles": []
            }
        ]
    }
    

解决方法

1. 直接定位SharePoint Online服务主体

SharePoint Online的服务主体有固定的应用ID:00000003-0000-0ff1-ce00-000000000000,使用这个ID发起Graph查询:

GET https://graph.microsoft.com/v1.0/servicePrincipals/00000003-0000-0ff1-ce00-000000000000?$select=displayName,appRoles

2. 提取目标角色ID

该请求返回的appRoles数组中,包含所有SharePoint Online的应用角色,找到你需要的对应角色(匹配截图中的第二项),其id字段即为租户专属的内部ID。

关键说明

之前查询为空的原因是:SharePoint Online服务主体的显示名称是Microsoft SharePoint Online,并非以SharePoint开头,因此startswith(displayName,'SharePoint')的过滤条件无法命中它。

内容的提问来源于stack exchange,提问作者vilmarci

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 23:31:05