You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

MIP SDK 文件保护失败与认证令牌不被服务接受问题求助

排查MIP CLI令牌认证与标签保护问题

让我们一步步拆解你遇到的问题,核心根源是MIP不同操作需要对应不同的权限范围,加上令牌缓存干扰导致后续操作出错,以下是具体解决方案:

1. 明确不同MIP操作的权限范围差异

你遇到的矛盾点(切换scope能保护但后续操作失败)是因为MIP的不同功能对应不同的资源URI:

  • 文件保护/解密:需要https://aadrm.com/.default作为scope
  • 标签管理、文件状态查询:需要https://psor.o365syncservice.com/.default作为scope

之前的脚本固定了单一scope,导致跨操作时令牌的受众(aud字段)不匹配,触发服务拒绝认证的错误。

2. 修改认证脚本支持动态指定Scope

调整你的auth.py,让它可以根据执行的操作传入对应scope,同时跳过静默令牌获取避免缓存干扰:

import sys
import logging
import msal

def main(argv):
    client_id = str(argv[0])
    tenant_id = str(argv[1])
    secret = str(argv[2])
    # 从命令行参数动态接收scope,默认使用标签操作的scope
    target_scope = [str(argv[3])] if len(argv) > 3 else ["https://psor.o365syncservice.com/.default"]
    authority = "https://login.microsoftonline.com/{}".format(tenant_id)
    
    app = msal.ConfidentialClientApplication(
        client_id, 
        authority=authority, 
        client_credential=secret
    )
    
    logging.info(f"Fetching new token for scope: {target_scope}")
    # 直接获取新令牌,避免缓存中旧令牌的干扰
    result = app.acquire_token_for_client(scopes=target_scope)
    
    if "access_token" in result:
        sys.stdout.write(result['access_token'])
    else:
        print(result.get("error"))
        print(result.get("error_description"))
        print(result.get("correlation_id"))

if __name__ == '__main__':
    main(sys.argv[1:])

3. 针对不同操作使用对应令牌

执行MIP CLI命令时,根据操作类型传入正确的scope生成令牌:

  • 应用带保护的标签:
    mip file label add --file "test.docx" --label-id "<你的标签GUID>" --protect --auth "$(python auth.py <client_id> <tenant_id> <secret> https://aadrm.com/.default)"
    
  • 查询文件状态/重新应用标签:
    mip file status --file "test.docx" --auth "$(python auth.py <client_id> <tenant_id> <secret> https://psor.o365syncservice.com/.default)"
    

4. 验证Azure AD应用权限配置

确保你的应用注册同时具备两类权限,并且已授予管理员同意:

  • Microsoft Information Protection Sync Service:添加应用权限(如File.Read.All、Label.Read.All、Label.Write.All)
  • Azure Rights Management Services:添加应用权限(如Content.DelegatedWriter、Content.DelegatedReader)

5. 验证令牌有效性

可以解码获取到的令牌(用jwt.ms工具),检查aud字段是否匹配:

  • 保护操作的令牌aud应为https://aadrm.com
  • 标签操作的令牌aud应为https://psor.o365syncservice.com

如果aud不匹配,说明scope指定错误,需要重新调整。

内容的提问来源于stack exchange,提问作者musay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 10:43:12