You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

多租户环境下用InteractiveBrowserCredential调用DataFactoryManagementClient遇令牌租户错误

跨租户环境下使用InteractiveBrowserCredential调用ADF管道的解决方案

你遇到的InvalidAuthenticationTokenTenant错误,核心原因是默认获取的令牌属于你账号所在的租户,而非ADF所在的目标租户——即使设置了additionally_allowed_tenants='*',也需要明确指定目标租户ID来获取匹配的令牌。以下是无需服务主体的解决方案:

解决方案1:明确指定ADF所在租户ID

修改InteractiveBrowserCredential的初始化参数,直接传入ADF所在租户的ID,引导身份验证流程针对目标租户生成令牌:

from azure.identity import InteractiveBrowserCredential
from azure.mgmt.datafactory import DataFactoryManagementClient

# 替换为ADF所属的租户ID
target_tenant_id = "<adf-tenant-id>"
credential = InteractiveBrowserCredential(tenant_id=target_tenant_id)
adf_client = DataFactoryManagementClient(credential=credential, subscription_id='<subscription-id>')

run_response = adf_client.pipelines.create_run(
    resource_group_name=rg_name, 
    factory_name=adf_name, 
    pipeline_name=pipeline_name, 
    parameters={'counter': '100'})

执行代码时,浏览器会弹出登录页面,此时你的账号会以目标租户的身份完成验证,获取的令牌就能正常调用ADF的管理API。

解决方案2:使用VS Code凭据(适用于VS Code开发场景)

如果你日常用VS Code开发,且已通过Azure Account插件登录并切换到ADF所在租户,可以直接使用VisualStudioCodeCredential,它会自动复用VS Code中当前活跃的租户身份:

from azure.identity import VisualStudioCodeCredential
from azure.mgmt.datafactory import DataFactoryManagementClient

credential = VisualStudioCodeCredential()
adf_client = DataFactoryManagementClient(credential=credential, subscription_id='<subscription-id>')

run_response = adf_client.pipelines.create_run(
    resource_group_name=rg_name, 
    factory_name=adf_name, 
    pipeline_name=pipeline_name, 
    parameters={'counter': '100'})

注意:需确保VS Code的Azure Account插件已切换到ADF所在的租户(可通过插件面板的租户列表切换)。

补充说明

并非完全无法使用跨租户令牌调用DataFactoryManagementClient,只是需要明确指定目标租户,让凭据服务生成对应租户的有效令牌。上述两种方案都可以绕过服务主体申请流程,直接用你的个人账号完成跨租户的ADF管道调用。

内容的提问来源于stack exchange,提问作者ar7

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 17:42:17