You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Bicep(或ARM模板)创建Microsoft Entra应用注册及应用角色?

别担心,完全可以用Bicep(或ARM模板)实现你用Terraform做的Microsoft Entra应用注册和应用角色配置——你之前踩的坑我也遇到过,Microsoft.Authorization/roleDefinitions是用来创建Azure RBAC角色的,和Entra应用的应用角色根本不是一回事。下面我给你对应Terraform步骤的实现方案:

步骤1:创建Entra应用注册(对应Terraform的azuread_application)

在Bicep中,我们使用Microsoft.AAD/applicationRegistrations资源来创建应用注册,对应你Terraform里的azuread_application资源。这里需要注意Terraform的type = "webapp/api"在Bicep中是通过配置web块和signInAudience属性来实现的:

// 定义参数,对应Terraform的local和var
param fullAppName string
param appOwners array

resource adApp 'Microsoft.AAD/applicationRegistrations@2023-04-01' = {
  name: fullAppName
  properties: {
    displayName: fullAppName
    // 对应Terraform的owners参数
    owners: appOwners
    // 设置受众,根据你的需求选择,比如AzureADMultipleOrgs(多租户)、AzureADandPersonalMicrosoftAccount等
    signInAudience: 'AzureADMyOrg'
    // 对应Terraform的type = "webapp/api",配置web应用相关属性
    web: {
      redirectUris: [] // 如果你的应用需要回调URL,可以在这里添加
    }
  }
}
步骤2:添加应用角色(对应Terraform的azuread_application_app_role)

和Terraform单独创建应用角色资源不同,Bicep中应用角色是直接作为应用注册资源的appRoles属性来配置的,不需要单独的资源。我们可以把角色定义直接写在应用注册的properties里:

param fullAppName string
param appOwners array

resource adApp 'Microsoft.AAD/applicationRegistrations@2023-04-01' = {
  name: fullAppName
  properties: {
    displayName: fullAppName
    owners: appOwners
    signInAudience: 'AzureADMyOrg'
    web: {
      redirectUris: []
    }
    // 这里配置应用角色数组,对应Terraform的azuread_application_app_role资源
    appRoles: [
      {
        // 对应Terraform的allowed_member_types
        allowedMemberTypes: [
          'Application'
        ]
        description: 'Person Reader can search and read persons'
        displayName: 'Person Reader'
        // 每个应用角色需要唯一的GUID,用Bicep内置的guid()函数自动生成
        id: guid()
        // 必须设置为true才能启用该角色
        isEnabled: true
        // 对应Terraform的value参数
        value: 'Persons.Read'
      }
    ]
  }
}
对应的ARM模板示例

如果你需要用ARM模板实现,结构和Bicep一致,只是语法不同:

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "fullAppName": {
      "type": "string"
    },
    "appOwners": {
      "type": "array"
    }
  },
  "resources": [
    {
      "type": "Microsoft.AAD/applicationRegistrations",
      "apiVersion": "2023-04-01",
      "name": "[parameters('fullAppName')]",
      "properties": {
        "displayName": "[parameters('fullAppName')]",
        "owners": "[parameters('appOwners')]",
        "signInAudience": "AzureADMyOrg",
        "web": {
          "redirectUris": []
        },
        "appRoles": [
          {
            "allowedMemberTypes": [
              "Application"
            ],
            "description": "Person Reader can search and read persons",
            "displayName": "Person Reader",
            "id": "[guid()]",
            "isEnabled": true,
            "value": "Persons.Read"
          }
        ]
      }
    }
  ]
}

关键说明

  • 应用角色是应用注册的内置属性,不需要单独创建资源,这和Terraform的方式不同,Terraform用单独的资源来管理,而Bicep/ARM是直接在应用注册里配置。
  • 每个应用角色必须有唯一的id,用guid()函数生成即可,不需要手动指定。
  • signInAudience的取值根据你的应用场景选择,确保和Terraform配置的行为一致。

内容的提问来源于stack exchange,提问作者Martin Wickman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 09:52:42