MIP SDK 文件保护失败与认证令牌不被服务接受问题求助
排查MIP CLI令牌认证与标签保护问题
让我们一步步拆解你遇到的问题,核心根源是MIP不同操作需要对应不同的权限范围,加上令牌缓存干扰导致后续操作出错,以下是具体解决方案:
1. 明确不同MIP操作的权限范围差异
你遇到的矛盾点(切换scope能保护但后续操作失败)是因为MIP的不同功能对应不同的资源URI:
- 文件保护/解密:需要
https://aadrm.com/.default作为scope - 标签管理、文件状态查询:需要
https://psor.o365syncservice.com/.default作为scope
之前的脚本固定了单一scope,导致跨操作时令牌的受众(aud字段)不匹配,触发服务拒绝认证的错误。
2. 修改认证脚本支持动态指定Scope
调整你的auth.py,让它可以根据执行的操作传入对应scope,同时跳过静默令牌获取避免缓存干扰:
import sys import logging import msal def main(argv): client_id = str(argv[0]) tenant_id = str(argv[1]) secret = str(argv[2]) # 从命令行参数动态接收scope,默认使用标签操作的scope target_scope = [str(argv[3])] if len(argv) > 3 else ["https://psor.o365syncservice.com/.default"] authority = "https://login.microsoftonline.com/{}".format(tenant_id) app = msal.ConfidentialClientApplication( client_id, authority=authority, client_credential=secret ) logging.info(f"Fetching new token for scope: {target_scope}") # 直接获取新令牌,避免缓存中旧令牌的干扰 result = app.acquire_token_for_client(scopes=target_scope) if "access_token" in result: sys.stdout.write(result['access_token']) else: print(result.get("error")) print(result.get("error_description")) print(result.get("correlation_id")) if __name__ == '__main__': main(sys.argv[1:])
3. 针对不同操作使用对应令牌
执行MIP CLI命令时,根据操作类型传入正确的scope生成令牌:
- 应用带保护的标签:
mip file label add --file "test.docx" --label-id "<你的标签GUID>" --protect --auth "$(python auth.py <client_id> <tenant_id> <secret> https://aadrm.com/.default)" - 查询文件状态/重新应用标签:
mip file status --file "test.docx" --auth "$(python auth.py <client_id> <tenant_id> <secret> https://psor.o365syncservice.com/.default)"
4. 验证Azure AD应用权限配置
确保你的应用注册同时具备两类权限,并且已授予管理员同意:
- Microsoft Information Protection Sync Service:添加应用权限(如
File.Read.All、Label.Read.All、Label.Write.All) - Azure Rights Management Services:添加应用权限(如
Content.DelegatedWriter、Content.DelegatedReader)
5. 验证令牌有效性
可以解码获取到的令牌(用jwt.ms工具),检查aud字段是否匹配:
- 保护操作的令牌
aud应为https://aadrm.com - 标签操作的令牌
aud应为https://psor.o365syncservice.com
如果aud不匹配,说明scope指定错误,需要重新调整。
内容的提问来源于stack exchange,提问作者musay
相关产品推荐
相关产品推荐

