使用Azure CLI创建应用后设置Azure App Scope报错求助
Azure AD应用添加Scope失败问题解决
问题背景
已成功创建Azure AD应用,但无法为其设置Scope,此前找到的相关解决方案已过时。
创建应用脚本
$appId = az ad app create --display-name "webapp - dev" --sign-in-audience "AzureADMyOrg" --required-resource-accesses "./appregistration/script.json" --query appId -o tsv
Scope配置文件(permissions.json)
[ { "adminConsentDescription": "Allow the app to access Api endpoints", "adminConsentDisplayName": "webApi", "id": null, "isEnabled": true, "type": "Admin", "userConsentDescription": null, "userConsentDisplayName": null, "value": "webApi" } ]
尝试的设置脚本
$json = Get-Content './appregistration/permissions.json' | Out-String | ConvertFrom-Json foreach ($element in $json) {$element.id = [guid]::NewGuid() } $apiScopeJson = @{oauth2PermissionScopes = $json} az ad app update --id $appId --set api=$apiScopeJson
错误信息
请求体中的api属性值不符合 schema 要求。(原错误:Property api in payload has a value that does not match schema.)
解决方案
问题根源在于直接传递PowerShell哈希表给az ad app update的--set参数时,CLI无法正确解析为符合要求的JSON结构。需要将对象转换为标准JSON字符串后再传递:
$json = Get-Content './appregistration/permissions.json' | Out-String | ConvertFrom-Json # 为每个Scope生成字符串格式的GUID foreach ($element in $json) { $element.id = [guid]::NewGuid().ToString() } # 将哈希表转换为深度足够的JSON字符串 $apiScopeJson = @{ oauth2PermissionScopes = $json } | ConvertTo-Json -Depth 10 # 用引号包裹JSON字符串,确保CLI正确解析 az ad app update --id $appId --set api="$apiScopeJson"
关键说明
- GUID格式:必须将生成的GUID转换为字符串类型,避免CLI解析时出现格式错误
- JSON转换深度:使用
-Depth 10确保嵌套结构被完整转换 - 引号包裹:将JSON字符串用双引号包裹,防止PowerShell或CLI拆分参数
内容的提问来源于stack exchange,提问作者Imran Ahmad Shahid
相关产品推荐
相关产品推荐

