You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Go语言检查Azure用户所属组?及401认证错误排查

问题:Azure Graph RBAC查询用户组时出现401认证错误

我编写了一段Go语言代码,使用Azure SDK的graphrbac模块,通过客户端凭证方式完成认证,用于查询Azure中指定用户所属的组。但运行代码时出现401错误,提示“访问令牌缺失或格式错误”,我已确认配置了必要权限,请求解决该问题。

代码如下:

package main

import (
    "context"
    "fmt"
    "log"

    "github.com/Azure/azure-sdk-for-go/services/graphrbac/1.6/graphrbac"
    //"github.com/Azure/go-autorest/autorest"
    "github.com/Azure/go-autorest/autorest/azure/auth"
)

const (
    clientID           = "" // 需填写你的客户端ID
    clientSecret       = "" // 需填写你的客户端密钥
    tenantID           = "" // 需填写你的租户ID
    userPrincipalName  = "username@myorg.com"
)

func main() {
    // 创建Azure认证授权器
    authorizer, err := auth.NewClientCredentialsConfig(clientID, clientSecret, tenantID).Authorizer()
    if err != nil {
        log.Fatalf("创建Azure授权器失败: %v", err)
    }

    // 创建Graph RBAC管理客户端
    graphClient := graphrbac.NewGroupsClient(tenantID)
    graphClient.Authorizer = authorizer
    fmt.Println("----")
    // 获取该用户所属的组
    groups, err := graphClient.List(context.TODO(), fmt.Sprintf("members/userPrincipalName eq '%s'", userPrincipalName))
    if err != nil {
        log.Fatalf("获取用户组失败: %v", err)
    }

    // 打印组名称
    for _, group := range groups.Values() {
        fmt.Println(*group.DisplayName)
    }
}

报错信息:

2023/06/22 23:40:24 获取用户组失败: graphrbac.GroupsClient#List: 请求响应失败: StatusCode=401 -- 原始错误: autorest/azure: 服务返回错误。Status=401 Code="Unknown" Message="未知服务错误" Details=[{"odata.error":{"code":"Authentication_MissingOrMalformed","message":{"lang":"en","value":"访问令牌缺失或格式错误。"}}}]

解决方法

核心问题

默认的NewClientCredentialsConfig会请求Azure资源管理器(ARM)的令牌,但你调用的是Azure AD Graph旧API,需要指定专门的资源标识符https://graph.windows.net,否则生成的令牌不被Graph API认可,导致401错误。

修改后的代码

仅需在创建凭证配置时添加资源指定:

package main

import (
    "context"
    "fmt"
    "log"

    "github.com/Azure/azure-sdk-for-go/services/graphrbac/1.6/graphrbac"
    "github.com/Azure/go-autorest/autorest/azure/auth"
)

const (
    clientID           = "你的客户端ID"
    clientSecret       = "你的客户端密钥"
    tenantID           = "你的租户ID"
    userPrincipalName  = "username@myorg.com"
)

func main() {
    // 创建客户端凭证配置,指定Azure AD Graph的资源ID
    credConfig := auth.NewClientCredentialsConfig(clientID, clientSecret, tenantID)
    credConfig.Resource = "https://graph.windows.net" // 关键修改点

    authorizer, err := credConfig.Authorizer()
    if err != nil {
        log.Fatalf("创建Azure授权器失败: %v", err)
    }

    graphClient := graphrbac.NewGroupsClient(tenantID)
    graphClient.Authorizer = authorizer

    groups, err := graphClient.List(context.TODO(), fmt.Sprintf("members/userPrincipalName eq '%s'", userPrincipalName))
    if err != nil {
        log.Fatalf("获取用户组失败: %v", err)
    }

    for _, group := range groups.Values() {
        fmt.Println(*group.DisplayName)
    }
}

额外检查项

  • 确认服务主体(对应clientID的应用)已被授予Azure AD Graph的Directory.Read.All应用权限,并且完成了管理员同意(客户端凭证流必须使用应用权限,委派权限不适用)。
  • 核对clientID、clientSecret、tenantID是否正确,无拼写错误或多余字符。

内容的提问来源于stack exchange,提问作者Nishant Singh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 08:03:19