You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Microsoft Graph筛选特定所有者的Azure AD应用程序

查找特定用户拥有的Azure AD应用程序

你之前遇到的错误确实是因为owners是多值集合属性,无法直接通过owners/address这种方式筛选集合内对象的子属性,必须用集合运算符来处理。以下是两种可行的解决方法:

方法一:使用$filter结合any运算符筛选

  1. 先获取目标用户的Object ID
    发送请求获取用户的唯一ID:

    GET https://graph.microsoft.com/v1.0/users?$filter=mail eq 'fulano.de.tal@mydomain.com'&$select=id
    

    响应中会返回该用户的id值,记下来备用。

  2. 用用户ID筛选其拥有的应用
    使用any运算符遍历owners集合,匹配用户ID:

    GET https://graph.microsoft.com/v1.0/applications?$filter=owners/any(o: o/id eq '{用户Object ID}')
    

方法二:直接通过用户的ownedObjects导航属性获取

利用用户对象的ownedObjects导航属性,直接筛选出类型为应用的资源:

GET https://graph.microsoft.com/v1.0/users/{用户Object ID}/ownedObjects/microsoft.graph.application

这种方式会直接返回该用户拥有的所有Azure AD应用程序,无需额外过滤。

注意事项

  • 不能直接在any运算符中使用mail属性进行匹配(比如owners/any(o: o/mail eq 'xxx')),Graph API的集合筛选规则不支持这种操作,必须通过用户的Object ID来匹配。
  • 确保你的Graph API权限足够(需要Application.Read.All或Directory.Read.All等相关权限)。

你之前收到的错误提示:
The parent value for a property access of a property 'address' is not a single value. Property access can only be applied to a single value.

内容的提问来源于stack exchange,提问作者Vaccano

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 16:42:25