You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ARM模板通过PowerShell部署Azure AD应用失败排查

ARM模板中PowerShell部署脚本创建Azure AD应用失败排查

问题场景

通过ARM模板的PowerShell部署脚本创建Azure AD应用时部署失败,错误提示:

The resource write operation failed to complete successfully, because it reached terminal provisioning state 'failed'

同时CLI执行相同操作也失败。使用的ARM模板代码如下:

{
    "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
    "contentVersion": "1.0.0.0",
    "parameters": {},
    "variables": {
        "cliResourceName": "AzAppRegDeploymentScript"
    },
    "resources": [
        {
            "type": "Microsoft.Resources/deploymentScripts",
            "apiVersion": "2019-10-01-preview",
            "name": "[variables('cliResourceName')]",
            "location": "[resourceGroup().location]",
            "kind": "AzurePowerShell",
            "identity": {
                "type": "UserAssigned",
                "userAssignedIdentities": {
                    "/subscriptions/XXXXX-bXXd-4XX5-b&*e-YDTXXYYYYS/resourceGroups/sample/providers/Microsoft.ManagedIdentity/userAssignedIdentities/mientity": {}
                }
            },
            "properties": {
                "azPowerShellVersion": "9.7",
                "timeout": "PT30M",
                "scriptContent": "$app = New-AzureADApplication -DisplayName 'app-d'",
                "cleanupPreference": "OnSuccess",
                "retentionInterval": "P1D"
            }
        }
    ]
}

已为用户托管标识“mientity”分配Contributor角色,且参考过微软官方权限配置文档。

可能的失败原因及解决步骤

  • 权限范围不匹配:Contributor是Azure资源管理器(ARM)的权限,无法用于Azure AD资源操作。创建Azure AD应用需要Azure AD内的权限,需为托管标识“mientity”分配Azure AD中的Application Developer或Application Administrator角色。
  • PowerShell模块及命令问题:New-AzureADApplication属于AzureAD模块,Az PowerShell 9.7环境默认未预装该模块,建议改用Az模块的New-AzADApplication命令,兼容性更好。
  • 缺少身份验证步骤:部署脚本中未通过托管标识完成Azure AD身份验证,需在创建应用的命令前添加身份验证逻辑。
  • 使用预览版API:Microsoft.Resources/deploymentScripts使用的2019-10-01-preview是预览版本,存在不确定性,建议改用稳定版API如2020-10-01。

修正后的模板示例

{
    "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
    "contentVersion": "1.0.0.0",
    "parameters": {},
    "variables": {
        "cliResourceName": "AzAppRegDeploymentScript"
    },
    "resources": [
        {
            "type": "Microsoft.Resources/deploymentScripts",
            "apiVersion": "2020-10-01",
            "name": "[variables('cliResourceName')]",
            "location": "[resourceGroup().location]",
            "kind": "AzurePowerShell",
            "identity": {
                "type": "UserAssigned",
                "userAssignedIdentities": {
                    "/subscriptions/XXXXX-bXXd-4XX5-b&*e-YDTXXYYYYS/resourceGroups/sample/providers/Microsoft.ManagedIdentity/userAssignedIdentities/mientity": {}
                }
            },
            "properties": {
                "azPowerShellVersion": "9.7",
                "timeout": "PT30M",
                "scriptContent": "Connect-AzAccount -Identity; $app = New-AzADApplication -DisplayName 'app-d'",
                "cleanupPreference": "OnSuccess",
                "retentionInterval": "P1D"
            }
        }
    ]
}

内容的提问来源于stack exchange,提问作者DAK

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 17:07:29