You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用Azure Function时API Management返回401未授权问题求助

APIM通过托管身份调用Azure管理API禁用Function时返回401 Unauthorized

问题场景

在Azure API Management的入站策略中,使用authentication-managed-identity获取令牌,调用Azure资源管理API的PATCH接口尝试禁用指定Function,但持续收到401 Unauthorized错误。当前使用的策略如下:

<policies>
<inbound>
    <base />
    <authentication-managed-identity resource="https://management.azure.com/" />
    <send-request mode="new" response-variable-name="managementResponse" timeout="20"
ignore-error="true">
        <set-url>https://management.azure.com/subscriptions/blablabla-bla-blalb-blablablablabla/resourceGroups/blabla-resourcegroup-blabla/providers/Microsoft.Web/sites/DummyFunction-Test/functions/DummyFunction-Test?api-version=2018-11-01</set-url>
        <set-method>PATCH</set-method>
        <set-header name="Content-Type" exists-action="override">
            <value>application/json</value>
        </set-header>
        <set-body>@{
            return new JObject(
                new JProperty("properties",
                    new JObject(
                        new JProperty("status", "disabled")
                    )
                )
            ).ToString();
        }</set-body>
    </send-request>
    <choose>
    <when condition="@(((IResponse)context.Variables["managementResponse"]).StatusCode
 == 401)">
                <return-response>
                <set-status code="401" reason="Unauthorized" />
                <set-body>@{
                        return "Authentication failed. Please check your Managed Identity setup.";
                    }</set-body>
            </return-response>
        </when>
   <when condition="@(((IResponse)context.Variables["managementResponse"]).StatusCode
== 403)">
            <return-response>
                <set-status code="403" reason="Forbidden" />
                <set-body>@{
                        return "Authorization failed. Managed Identity does not have sufficient permissions.";
                    }</set-body>
            </return-response>
        </when>
    </choose>
</inbound>
<backend>
    <base />
</backend>
<outbound>
    <base />
</outbound>
<on-error>
    <base />
</on-error> </policies>

自身账号拥有Contributor角色,但问题仍未解决。

排查与解决方案

1. 确认APIM托管身份配置正确性

  • 检查APIM实例是否已启用系统分配或用户分配托管身份:
    • 系统分配身份:APIM实例 -> 身份 -> 系统分配 -> 状态为“开启”
    • 用户分配身份:需在策略中添加client-id属性,例如:<authentication-managed-identity resource="https://management.azure.com/" client-id="你的用户分配身份ID" />
  • 确保托管身份已成功创建,无配置错误。

2. 验证令牌受众与获取状态

  • 查看APIM跟踪日志,确认<authentication-managed-identity>步骤是否成功获取到令牌:
    • 检查令牌的aud声明是否为https://management.azure.com/,受众不匹配会直接导致401
    • 如果日志显示令牌获取失败,排查托管身份的权限或Azure AD配置问题

3. 给APIM托管身份分配权限(关键!)

注意:用户自身的Contributor角色不生效,必须为APIM的托管身份分配对应权限:

  • 前往目标Function App或其所在资源组 -> 访问控制(IAM) -> 添加角色分配
  • 角色选择Contributor或更细粒度的Web Site Contributor
  • 成员选择APIM的托管身份(系统分配身份直接选APIM实例名,用户分配身份选对应的身份资源)
  • 完成分配后等待几分钟(权限可能有延迟)再测试

4. 检查API调用的URL与版本

  • 确认URL中的订阅ID、资源组名、Function App名、函数名称完全正确,无拼写错误
  • 尝试将api-version更新为最新稳定版(如2022-09-01),避免旧版本兼容性问题

5. 测试托管身份权限有效性

  • 使用Azure CLI模拟托管身份调用:
    # 若为系统分配身份(需在APIM所在环境执行,或使用用户分配身份的client-id)
    az login --identity --username /subscriptions/[订阅ID]/resourceGroups/[资源组名]/providers/Microsoft.ApiManagement/service/[APIM实例名]
    # 调用禁用函数的API
    az rest --method patch --uri "https://management.azure.com/subscriptions/[订阅ID]/resourceGroups/[资源组名]/providers/Microsoft.Web/sites/[Function App名]/functions/[函数名]?api-version=2022-09-01" --body '{"properties":{"status":"disabled"}}'
    
  • 如果此命令返回成功,说明权限配置正确,问题出在APIM策略或令牌获取环节;如果仍报错,继续排查托管身份的权限配置

内容的提问来源于stack exchange,提问作者MadDev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 11:41:06