使用PowerShell获取AccessToken后无法登录ExchangeOnline与AzureAD
问题:使用刷新令牌获取AccessToken后无法连接ExchangeOnline和AzureAD
我通过刷新令牌成功获取了访问令牌,但调用Connect-ExchangeOnline和Connect-AzAccount时均失败,具体代码如下:
$clientId = "7b2cd291-87e9-49fc-888e-xxxxxxxxxxxx" $clientSecret = "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" $tenantId = "baf62cb4-4cc6-4af9-a3c1-xxxxxxxxxxxx" $refreshToken = "xxxxxxxx..." $headers = New-Object "System.Collections.Generic.Dictionary[[String],[String]]" $headers.Add("Content-Type", "application/x-www-form-urlencoded") $body = "client_id=" + $clientId + "&scope=https%3A%2F%2Fgraph.microsoft.com%2F.default&refresh_token=" + $refreshToken + "&grant_type=refresh_token&client_secret=" + $clientSecret $url = "https://login.microsoftonline.com/" + $tenantId + "/oauth2/v2.0/token" $response = Invoke-RestMethod $url -Method 'POST' -Headers $headers -Body $body Connect-ExchangeOnline -UserPrincipalName divyesh@myorg.com -AccessToken $response.access_token Connect-AzAccount -AccessToken $response.access_token -AccountId 'divyesh@myorg.com'
ExchangeOnline连接错误
UnAuthorized At C:\Program Files\WindowsPowerShell\Modules\ExchangeOnlineManagement\3.1.0\netFramework\ExchangeOnlineManagement.psm1:733 char:21 + throw $_.Exception; + ~~~~~~~~~~~~~~~~~~ + CategoryInfo : OperationStopped: (:) [], UnauthorizedAccessException + FullyQualifiedErrorId : UnAuthorized
AzureAD连接错误
WARNING: Unable to acquire a token for tenant 'organizations' with error 'Authentication failed.' Connect-AzAccount : Authentication failed. At line:16 char:1 + Connect-AzAccount -AccessToken $response.access_token -AccountId 'div ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : CloseError: (:) [Connect-AzAccount], CloudException + FullyQualifiedErrorId : Microsoft.Azure.Commands.Profile.ConnectAzureRmAccountCommand
可能的原因及解决方法
- 权限范围不匹配:当前请求的scope仅包含
https://graph.microsoft.com/.default,但ExchangeOnline和Az模块需要各自的API权限范围:- 连接ExchangeOnline需添加
https://outlook.office365.com/.default(或具体Exchange权限) - 连接AzAccount需添加
https://management.azure.com/.default(或Azure管理权限)
修改请求body中的scope参数,合并多个scope(URL编码后用%20分隔):
$body = "client_id=" + $clientId + "&scope=https%3A%2F%2Fgraph.microsoft.com%2F.default%20https%3A%2F%2Foutlook.office365.com%2F.default%20https%3A%2F%2Fmanagement.azure.com%2F.default&refresh_token=" + $refreshToken + "&grant_type=refresh_token&client_secret=" + $clientSecret - 连接ExchangeOnline需添加
- 令牌受众验证:解码获取的AccessToken,确认
aud(受众)字段包含对应服务的URL:ExchangeOnline对应https://outlook.office365.com,Az对应https://management.azure.com。 - 应用注册权限配置:在Azure AD应用注册中,添加Exchange Online和Azure管理的应用权限并授予管理员同意,例如:
- Exchange Online:
Exchange.ManageAsApp(应用权限) - Azure管理:根据需求添加
Directory.Read.All、Subscription.Read.All等权限
- Exchange Online:
- Connect-AzAccount参数修正:指定
-TenantId参数,避免默认租户匹配问题:Connect-AzAccount -AccessToken $response.access_token -AccountId 'divyesh@myorg.com' -TenantId $tenantId - ExchangeOnline连接参数修正:使用AccessToken连接时无需指定
-UserPrincipalName,改为指定组织租户ID:Connect-ExchangeOnline -AccessToken $response.access_token -Organization $tenantId
内容的提问来源于stack exchange,提问作者Divyesh Jesadiya
相关产品推荐
相关产品推荐

