You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Pipelines中从组织NuGet源还原包时遇403权限错误,求助识别对应用户并解决

Fixing 403 Forbidden Error with NuGet Restore in Azure Pipelines (Unknown User GUID)

Hey there, I've run into this exact issue before—don't worry, that mysterious GUID isn't a "missing user" you need to hunt down in your organization. Let me break down what's going on and how to fix it:

What's That User GUID?

The ID b55d7ea1-921b-49df-87fe-761c8c8988d0 isn't a regular user account—it's the service principal identity that Azure Pipelines uses to run your pipeline jobs. This is an automatically generated identity tied to your project's build service, so you won't find it in your organization's standard user list.

How to Grant the Required ReadPackages Permission

Follow these steps to give the pipeline service identity access to your TEC-Get feed:

  • Go to your Azure DevOps organization and navigate to the Artifacts hub.
  • Locate your TEC-Get feed, click the gear icon (⚙️) in the top right corner to open feed settings.
  • Select the Permissions tab from the left menu.
  • Click Add users/groups—you have two reliable options here:
    1. Search for Project Collection Build Service (YourOrganizationName) (this is the generic build service identity linked to your project)
    2. Or directly paste the GUID b55d7ea1-921b-49df-87fe-761c8c8988d0 into the search box (it will resolve correctly even if it doesn't show up in regular user searches)
  • Assign the Reader role to this identity (this maps directly to the ReadPackages permission mentioned in the error) and save your changes.

Additional Troubleshooting Tips

  • Double-check your pipeline configuration: Ensure vstsFeed: 'TEC-Get' matches the exact, case-sensitive name of your feed.
  • If the DotNetCoreCLI@2 task still gives issues, try switching to the NuGetCommand@2 task instead—sometimes it handles feed permissions more reliably:
    - task: NuGetCommand@2
      displayName: NuGet restore
      inputs:
        command: 'restore'
        restoreSolution: '**/*.sln'
        feedsToUse: 'select'
        vstsFeed: 'TEC-Get'
    
  • Verify scope alignment: If your feed is scoped to a specific project, make sure you're granting permissions to the Project-level Build Service identity, not the organization-wide one.

内容的提问来源于stack exchange,提问作者rob

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 11:04:06