You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Get-AzureADWHfBKeys遇Azure登录错误500119:URN重定向URI被禁用

解决Get-AzureADWHfBKeys执行时的Azure登录错误500119

问题背景

执行Get-AzureADWHfBKeys清理Windows Hello for Business孤立密钥时,触发Azure登录错误500119,提示禁止使用urn:方案的重定向URI,要求改用https://login.microsoftonline.com/common/oauth2/nativeclient,涉及应用为Azure Active Directory PowerShell(ID: 1b730954-1685-4b74-9bfd-dac224a7b894),资源为Windows Azure Active Directory(ID: 00000002-0000-0000-c000-000000000000)。

解决方案

通过手动指定合规的重定向URI获取访问令牌,再传入目标命令即可解决:

  1. 导入已安装的模块:
Import-Module WHfBTools
Import-Module MSAL.PS -RequiredVersion 4.5.1.1
  1. 使用MSAL.PS获取符合要求的访问令牌:
# 替换为实际租户ID/域名
$tenantId = "example"
# 替换为目标用户的UPN
$targetUPN = "example"

$clientId = "1b730954-1685-4b74-9bfd-dac224a7b894"
$resourceId = "00000002-0000-0000-c000-000000000000"
$validRedirectUri = "https://login.microsoftonline.com/common/oauth2/nativeclient"

$token = Get-MsalToken -ClientId $clientId -TenantId $tenantId -Resource $resourceId -RedirectUri $validRedirectUri
  1. 传入令牌执行清理命令:
Get-AzureADWHfBKeys -Tenant $tenantId -UserPrincipalName $targetUPN -AccessToken $token.AccessToken

关键说明

  • 错误根源是WHfBTools模块默认使用的urn:格式重定向URI已被Azure AD限制,改用官方允许的nativeclient URI即可绕过。
  • 确保执行命令的账号拥有Azure AD全局管理员或身份验证管理员权限,否则无法管理Windows Hello for Business密钥。

内容的提问来源于stack exchange,提问作者Eddard Stark

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 05:36:07