You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用PowerShell获取AccessToken后无法登录ExchangeOnline与AzureAD

问题:使用刷新令牌获取AccessToken后无法连接ExchangeOnline和AzureAD

我通过刷新令牌成功获取了访问令牌,但调用Connect-ExchangeOnline和Connect-AzAccount时均失败,具体代码如下:

$clientId = "7b2cd291-87e9-49fc-888e-xxxxxxxxxxxx"
$clientSecret = "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
$tenantId = "baf62cb4-4cc6-4af9-a3c1-xxxxxxxxxxxx"
$refreshToken = "xxxxxxxx..."
$headers = New-Object "System.Collections.Generic.Dictionary[[String],[String]]"
$headers.Add("Content-Type", "application/x-www-form-urlencoded")

$body = "client_id=" + $clientId + "&scope=https%3A%2F%2Fgraph.microsoft.com%2F.default&refresh_token=" + $refreshToken + "&grant_type=refresh_token&client_secret=" + $clientSecret

$url = "https://login.microsoftonline.com/" + $tenantId + "/oauth2/v2.0/token"
$response = Invoke-RestMethod $url -Method 'POST' -Headers $headers -Body $body

Connect-ExchangeOnline -UserPrincipalName divyesh@myorg.com -AccessToken $response.access_token
Connect-AzAccount -AccessToken $response.access_token -AccountId 'divyesh@myorg.com'

ExchangeOnline连接错误

UnAuthorized
At C:\Program Files\WindowsPowerShell\Modules\ExchangeOnlineManagement\3.1.0\netFramework\ExchangeOnlineManagement.psm1:733 char:21
+                     throw $_.Exception;
+                     ~~~~~~~~~~~~~~~~~~
+ CategoryInfo          : OperationStopped: (:) [], UnauthorizedAccessException
+ FullyQualifiedErrorId : UnAuthorized

AzureAD连接错误

WARNING: Unable to acquire a token for tenant 'organizations' with error 'Authentication failed.'
Connect-AzAccount : Authentication failed.
At line:16 char:1
+ Connect-AzAccount -AccessToken $response.access_token -AccountId 'div ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo          : CloseError: (:) [Connect-AzAccount], CloudException
+ FullyQualifiedErrorId : Microsoft.Azure.Commands.Profile.ConnectAzureRmAccountCommand

可能的原因及解决方法

  • 权限范围不匹配:当前请求的scope仅包含https://graph.microsoft.com/.default,但ExchangeOnline和Az模块需要各自的API权限范围:
    • 连接ExchangeOnline需添加https://outlook.office365.com/.default(或具体Exchange权限)
    • 连接AzAccount需添加https://management.azure.com/.default(或Azure管理权限)
      修改请求body中的scope参数,合并多个scope(URL编码后用%20分隔):
    $body = "client_id=" + $clientId + "&scope=https%3A%2F%2Fgraph.microsoft.com%2F.default%20https%3A%2F%2Foutlook.office365.com%2F.default%20https%3A%2F%2Fmanagement.azure.com%2F.default&refresh_token=" + $refreshToken + "&grant_type=refresh_token&client_secret=" + $clientSecret
    
  • 令牌受众验证:解码获取的AccessToken,确认aud(受众)字段包含对应服务的URL:ExchangeOnline对应https://outlook.office365.com,Az对应https://management.azure.com。
  • 应用注册权限配置:在Azure AD应用注册中,添加Exchange Online和Azure管理的应用权限并授予管理员同意,例如:
    • Exchange Online:Exchange.ManageAsApp(应用权限)
    • Azure管理:根据需求添加Directory.Read.All、Subscription.Read.All等权限
  • Connect-AzAccount参数修正:指定-TenantId参数,避免默认租户匹配问题:
    Connect-AzAccount -AccessToken $response.access_token -AccountId 'divyesh@myorg.com' -TenantId $tenantId
    
  • ExchangeOnline连接参数修正:使用AccessToken连接时无需指定-UserPrincipalName,改为指定组织租户ID:
    Connect-ExchangeOnline -AccessToken $response.access_token -Organization $tenantId
    

内容的提问来源于stack exchange,提问作者Divyesh Jesadiya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 11:52:22