如何通过PowerShell使用AAD应用注册连接Azure Analysis Service服务器
使用Azure应用注册连接Azure Analysis Service(PowerShell)
你需要针对Azure Analysis Service的资源ID获取访问令牌,并通过包含令牌的连接字符串完成连接。以下是修改后的完整代码:
# 使用个人凭据的代码(保留参考) $ServerFullName = "asazure://azureregion.asazure.windows.net/mytestanalysisservice" $Server = New-Object Microsoft.AnalysisServices.Server $Server.Connect($ServerFullName) $Server.Roles.ExternalMembers $Database = $Server.Databases.Item("adventureworks") # 使用Azure应用注册连接的完整代码 $SubscriptionID = "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" $TenantID = "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" $ApplicationID = "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" $PlainPassword = "ClientSecretValue" $SecuredPassword = ConvertTo-SecureString $PlainPassword -AsPlainText -Force $Credential = New-Object -TypeName System.Management.Automation.PSCredential -ArgumentList $ApplicationID, $SecuredPassword # 登录服务主体 Connect-AzAccount -ServicePrincipal -SubscriptionId $SubscriptionID -TenantId $TenantID -Credential $Credential -ErrorAction Stop $azContext = Get-AzContext # 生成针对Azure Analysis Service的访问令牌 # 注意:资源ID必须是https://asazure.windows.net/,这是AAS的固定资源标识 $aasResourceId = "https://asazure.windows.net/" $azProfile = [Microsoft.Azure.Commands.Common.Authentication.Abstractions.AzureRmProfileProvider]::Instance.Profile $profileClient = New-Object -TypeName Microsoft.Azure.Commands.ResourceManager.Common.RMProfileClient -ArgumentList ($azProfile) $token = $profileClient.AcquireAccessToken($TenantID, $aasResourceId) # 使用令牌连接Azure Analysis Service $ServerFullName = "asazure://azureregion.asazure.windows.net/mytestanalysisservice" # 构建包含令牌的连接字符串 $connectionString = "$ServerFullName;User ID=app:$ApplicationID@$TenantID;Password=$($token.AccessToken);Provider=MSOLAP" $Server.Connect($connectionString) # 验证连接(可选) Write-Host "已连接到AAS服务器: $($Server.Name)" $Database = $Server.Databases.Item("adventureworks") Write-Host "获取到数据库: $($Database.Name)"
关键修改说明:
- 令牌获取目标:必须指定Azure Analysis Service的资源ID
https://asazure.windows.net/,而非仅传入租户ID,这样才能拿到针对AAS的有效令牌。 - 连接字符串格式:用
User ID=app:<应用ID>@<租户ID>标识服务主体,将令牌作为密码传入,同时指定MSOLAP提供者。 - 错误处理:移除
SilentlyContinue,改用ErrorAction Stop便于排查登录环节的问题。
内容的提问来源于stack exchange,提问作者Vinny
相关产品推荐
相关产品推荐

