ARM模板通过PowerShell部署Azure AD应用失败排查
ARM模板中PowerShell部署脚本创建Azure AD应用失败排查
问题场景
通过ARM模板的PowerShell部署脚本创建Azure AD应用时部署失败,错误提示:
The resource write operation failed to complete successfully, because it reached terminal provisioning state 'failed'
同时CLI执行相同操作也失败。使用的ARM模板代码如下:
{ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": {}, "variables": { "cliResourceName": "AzAppRegDeploymentScript" }, "resources": [ { "type": "Microsoft.Resources/deploymentScripts", "apiVersion": "2019-10-01-preview", "name": "[variables('cliResourceName')]", "location": "[resourceGroup().location]", "kind": "AzurePowerShell", "identity": { "type": "UserAssigned", "userAssignedIdentities": { "/subscriptions/XXXXX-bXXd-4XX5-b&*e-YDTXXYYYYS/resourceGroups/sample/providers/Microsoft.ManagedIdentity/userAssignedIdentities/mientity": {} } }, "properties": { "azPowerShellVersion": "9.7", "timeout": "PT30M", "scriptContent": "$app = New-AzureADApplication -DisplayName 'app-d'", "cleanupPreference": "OnSuccess", "retentionInterval": "P1D" } } ] }
已为用户托管标识“mientity”分配Contributor角色,且参考过微软官方权限配置文档。
可能的失败原因及解决步骤
- 权限范围不匹配:Contributor是Azure资源管理器(ARM)的权限,无法用于Azure AD资源操作。创建Azure AD应用需要Azure AD内的权限,需为托管标识“mientity”分配Azure AD中的Application Developer或Application Administrator角色。
- PowerShell模块及命令问题:
New-AzureADApplication属于AzureAD模块,Az PowerShell 9.7环境默认未预装该模块,建议改用Az模块的New-AzADApplication命令,兼容性更好。 - 缺少身份验证步骤:部署脚本中未通过托管标识完成Azure AD身份验证,需在创建应用的命令前添加身份验证逻辑。
- 使用预览版API:
Microsoft.Resources/deploymentScripts使用的2019-10-01-preview是预览版本,存在不确定性,建议改用稳定版API如2020-10-01。
修正后的模板示例
{ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": {}, "variables": { "cliResourceName": "AzAppRegDeploymentScript" }, "resources": [ { "type": "Microsoft.Resources/deploymentScripts", "apiVersion": "2020-10-01", "name": "[variables('cliResourceName')]", "location": "[resourceGroup().location]", "kind": "AzurePowerShell", "identity": { "type": "UserAssigned", "userAssignedIdentities": { "/subscriptions/XXXXX-bXXd-4XX5-b&*e-YDTXXYYYYS/resourceGroups/sample/providers/Microsoft.ManagedIdentity/userAssignedIdentities/mientity": {} } }, "properties": { "azPowerShellVersion": "9.7", "timeout": "PT30M", "scriptContent": "Connect-AzAccount -Identity; $app = New-AzADApplication -DisplayName 'app-d'", "cleanupPreference": "OnSuccess", "retentionInterval": "P1D" } } ] }
内容的提问来源于stack exchange,提问作者DAK
相关产品推荐
相关产品推荐

