Azure Runbook迁移至托管身份后Set-AzureADMSServicePrincipal执行失败求助
问题:Azure Runbook托管身份调用Set-AzureADMSServicePrincipal失败
正在将Azure Runbook中的Run As Account迁移至托管身份,其他操作均正常,但AzureADPreview模块的Set-AzureADMSServicePrincipal cmdlet无法识别已存在的服务主体ID,该托管身份账户可正常使用其他cmdlet。
Runbook基于PowerShell 5.1,代码如下:
Import-Module AzureADPreview #Connect Managed-Identity Account Connect-AzAccount -Identity -AccountId "7a948a55-81e4-44fb-a6f0-ae11082d9125" #Connect AzureAD $context = [Microsoft.Azure.Commands.Common.Authentication.Abstractions.AzureRmProfileProvider]::Instance.Profile.DefaultContext $graphToken = [Microsoft.Azure.Commands.Common.Authentication.AzureSession]::Instance.AuthenticationFactory.Authenticate($context.Account, $context.Environment, $context.Tenant.Id.ToString(), $null, [Microsoft.Azure.Commands.Common.Authentication.ShowDialog]::Never, $null, "https://graph.microsoft.com").AccessToken $aadToken = [Microsoft.Azure.Commands.Common.Authentication.AzureSession]::Instance.AuthenticationFactory.Authenticate($context.Account, $context.Environment, $context.Tenant.Id.ToString(), $null, [Microsoft.Azure.Commands.Common.Authentication.ShowDialog]::Never, $null, "https://graph.windows.net").AccessToken Connect-AzureAD -AadAccessToken $aadToken -AccountId $context.Account.Id -TenantId $context.tenant.id #The cmdlet Set-AzureADMSServicePrincipal -Id 86ddbfda-9004-4b3a-b199-b1223c556cb1 -AppRoleAssignmentRequired $False
执行上述代码时,Set-AzureADMSServicePrincipal报错:
"Object reference not set to an instance of an object."
该服务主体ID在AzureAD中确实存在,且使用Run As Account执行相同cmdlet可正常运行。
已尝试以下操作但均无效:
- 重新安装AzureADPreview模块
- 创建PowerShell 7.x版本的Runbook
其他cmdlet均可通过托管身份正常调用,仅Set-AzureADMSServicePrincipal执行失败。
更新1
改用MS Graph模块连接成功,但执行Update-MgServicePrincipal时触发内部服务器错误。
代码如下:
Import-Module Microsoft.Graph.Applications Disable-AzContextAutosave -Scope Process $AzureContext = (Connect-AzAccount -Identity).context $AzureContext = Set-AzContext -SubscriptionName $AzureContext.Subscription -DefaultProfile $AzureContext $AppId = 'appid' $TenantId = 'tenantid' $servicePrincipalId = 'serviceId' $cert = (Get-AzAutomationCertificate -ResourceGroupName "resourcename" -AutomationAccountName "accname" -Name "certname").Thumbprint Connect-MgGraph -CertificateThumbprint $cert -TenantId $TenantId -ClientId $AppId $params = @{ SLBApplications = @{ "@odata.type" = "#Microsoft.DirectoryServices.CustomSecurityAttributeValue" attr1 ="test" attr2="test" } } Update-MgServicePrincipal -ServicePrincipalId $servicePrincipalId -BodyParameter $params
执行结果报错:
[Service_InternalServerError] : Encountered an internal server error.
内容的提问来源于stack exchange,提问作者Thao Le
相关产品推荐
相关产品推荐

