Azure Event Grid用内置角色权限替代SAS Key认证失败求助
问题:Azure WebApp使用托管身份向Event Grid Topic发送消息失败
我有一个部署在Azure上的WebApp,原本使用SAS Key向同订阅下的Azure Event Grid Topic发送消息。现在需要取消SAS Key的使用,改用内置角色与权限,且确保该WebApp是该Event Grid Topic的唯一消息来源。
我尝试了两种代码方案,但均无法正常工作:
方案1
Uri endpoint = new Uri(topicEndpoint); EventGridPublisherClient client = new EventGridPublisherClient(endpoint, new DefaultAzureCredential()); gridEvent = new EventGridEvent( subject: eventType, eventType: eventType, dataVersion: "1.0", data: new { Property1 = "Property1Value", Property2 = "Property12Value" } ); var result = client.SendEventAsync(gridEvent); returnResponse = result.Result.ToString();
方案2
Uri endpoint = new Uri(topicEndpoint); EventGridPublisherClient client = new EventGridPublisherClient(endpoint, new DefaultAzureCredential( new DefaultAzureCredentialOptions() { ManagedIdentityClientId = clientId } )); gridEvent = new EventGridEvent( subject: eventType, eventType: eventType, dataVersion: "1.0", data: new { Property1 = "Property1Value", Property2 = "Property12Value" } ); var result = client.SendEventAsync(gridEvent); returnResponse = result.Result.ToString();
//注:clientId为对应截图中的应用ID
我持续收到错误:
GraphQL error: 发生一个或多个错误。(发生一个或多个错误。(DefaultAzureCredential 无法从包含的凭据中检索令牌。- EnvironmentCredential 身份验证不可用。环境变量未完全配置。- WorkloadIdentityCredential 身份验证不可用。工作负载选项未完全配置。- ManagedIdentityCredential 身份验证不可用。多次尝试从托管身份端点获取令牌均失败。- 无法访问Visual Studio令牌提供程序,路径为D:\DWASFiles\Sites\sbx-job-web-int\LocalAppData.IdentityService\AzureServiceAuth\tokenprovider.json - 未安装Azure CLI - 未安装Az.Account模块 >= 2.2.0 - 找不到Azure Developer CLI。))
补充WebApp相关配置截图后,两种方案仍无法向Topic发送消息,请问我是否遗漏了什么配置?
内容的提问来源于stack exchange,提问作者Xander Kage
相关产品推荐
相关产品推荐

