You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Graph API PATCH请求重置AAD用户密码返回403 Forbidden

AAD用户密码重置403错误排查与解决方案

问题场景

我尝试用代码重置原生AAD用户密码,但收到403 Forbidden响应,相关代码、请求及响应详情如下:

代码实现

HttpResponseMessage createResponse = new();
RequestBodyPwReset requestBodyPWReset = new ()
{
    passwordProfile = new PasswordProfile()
    {
        forceChangePasswordNextSignIn = true,
        password = newPassword
    }
};
string jsonObj = JsonConvert.SerializeObject(requestBodyPWReset);
string uri = Constants.UrlToCreateLocalUserInAad + "/"+userAadId;

var httpRequestMessage = new HttpRequestMessage
{
    Method = HttpMethod.Patch,
    RequestUri = new Uri(uri),
    Headers =
            {
                { HttpRequestHeader.Accept.ToString(), "application/json" }
            },
    Content = new StringContent(jsonObj, Encoding.UTF8, "application/json")
};
httpRequestMessage.Headers.Add("Authorization", token);

try
{
    createResponse = new HttpClient().Send(httpRequestMessage);
    if (createResponse != null && createResponse.IsSuccessStatusCode)
    {
        string createResponseData = createResponse.Content.ReadAsStringAsync().Result;
        return "OK";
    }
    else
    {
        return "Sorry, try again. " + createResponse.ReasonPhrase + "---------- " + createResponse.RequestMessage.ToString();
    }
}
catch (Exception ex)
{
    string exMsg = ex.Message ?? "";
    string exInner = ex.InnerException == null ? "" : ex.InnerException.Message ?? "";
    return "Sorry, try again.";
}

请求详情

已通过AAD租户ID和企业应用客户端ID获取访问令牌并添加到请求头,请求信息:

{
    Method: PATCH, RequestUri: 'https://graph.microsoft.com/v1.0/users/8e91ee04-0e5d-4628-b555-f8caca9e4a27', Version: 1.1, Content: System.Net.Http.StringContent, Headers:
  {
      Accept: application/json
      Authorization: Bearer eyJ0exxxxxxxxxxxxxxxxxxxxxxxxxxxx
      traceparent: 00-a7e3149c95c5f61e53c154d57eabd0cd-12e7097ec88ffaaa-00
      Content-Type: application/json; charset=utf-8
      Content-Length: 81
  }
}

响应详情

{
    StatusCode: 403, ReasonPhrase: 'Forbidden', Version: 1.1, Content: System.Net.Http.HttpConnectionResponseContent, Headers:
    {
        Cache-Control: no-cache
        Transfer-Encoding: chunked
        Strict-Transport-Security: max-age=31536000
        request-id: 24908338-9c31-4d96-9828-6427d7d1d938
        client-request-id: 24908338-xxxx-xxxx-xxxx-6427d7d1d938
        x-ms-ags-diagnostic: {"ServerInfo":{"DataCenter":"South India","Slice":"E","Ring":"2","ScaleUnit":"002","RoleInstance":"MA1PEPF0000273D"}}
        x-ms-resource-unit: 1
        Date: Thu, 06 Jul 2023 09:52:04 GMT
        Content-Type: application/json
    }, Trailing Headers:
{
}}

错误排查与解决方案

1. 权限配置问题

403错误最常见原因是权限不足:

  • 重置AAD用户密码必须使用Application权限(Delegated权限不支持此操作),需配置User.ReadWrite.All或Directory.ReadWrite.All权限。
  • 权限添加后必须完成管理员同意,仅添加权限未授权仍会返回403。

2. 令牌验证

  • 解码访问令牌(用本地JWT解析工具),检查roles字段是否包含上述所需权限。
  • 确认令牌的aud(受众)字段为https://graph.microsoft.com,避免令牌用于其他服务。

3. 请求格式检查

  • 确保passwordProfile中的密码符合AAD租户的密码策略(长度、复杂度要求)。
  • 验证Constants.UrlToCreateLocalUserInAad的值为https://graph.microsoft.com/v1.0/users,拼接后的请求URI完整正确。

4. 替代实现方式

使用Microsoft Graph SDK(推荐)

官方SDK可减少手动构建请求的错误,示例代码:

using Microsoft.Graph;
using Azure.Identity;

var scopes = new[] { "User.ReadWrite.All" };
var tenantId = "你的租户ID";
var clientId = "你的客户端ID";
var clientSecret = "你的客户端密钥";

var clientSecretCredential = new ClientSecretCredential(tenantId, clientId, clientSecret);
var graphClient = new GraphServiceClient(clientSecretCredential, scopes);

var user = new User
{
    PasswordProfile = new PasswordProfile
    {
        ForceChangePasswordNextSignIn = true,
        Password = "新密码"
    }
};

await graphClient.Users["用户ID"].PatchAsync(user);

确认用户类型

确保目标用户是原生AAD用户,外部/B2B用户的密码重置需由其原租户处理。

5. 其他排查点

  • 检查企业应用是否被授予Microsoft Graph权限,避免混淆AAD Graph与Microsoft Graph服务。
  • 确认服务主体(企业应用)未被AAD条件访问策略限制。

内容的提问来源于stack exchange,提问作者Mainak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 16:57:44