关于Microsoft Graph登录审计日志API中内部用户被标记为来宾用户的技术问询
问题描述
我正在使用Microsoft Graph的登录REST API检索租户中的来宾用户登录记录,但发现部分登录记录里,内部用户的User Type属性被显示为Guest,同时观察到HomeTenantId与ResourceTenantId也存在差异。我注意到,在登录Azure AD门户时,有时会登录到之前登录过的租户目录,这种情况下TenantId会不同,且userType属性会显示为Guest,但对于SharePoint场景下出现的用户类型标记为来宾的情况,我无法确定原因,对此感到困惑。请问为何内部用户会被显示为来宾用户?
请求API地址:
https://graph.microsoft.com/beta/auditLogs/signIns
示例响应:
{ "id": "$$$$$$", "createdDateTime": "2021-08-29T10:22:06Z", "userDisplayName": "user", "userPrincipalName": "user@cortana.onmicrosoft.com", "userId": "$$$$$", "appId": "08e18876-6177-487e-b8b5-cf950c1e598c", "appDisplayName": "SharePoint Online Web Client Extensibility", "ipAddress": "$$$$$$", "ipAddressFromResourceProvider": null, "clientAppUsed": "", "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36", "correlationId": "*********", "conditionalAccessStatus": "notApplied", "originalRequestId": "", "isInteractive": true, "tokenIssuerName": "", "tokenIssuerType": "AzureAD", "processingTimeInMilliseconds": 173, "riskDetail": "none", "riskLevelAggregated": "none", "riskLevelDuringSignIn": "none", "riskState": "none", "riskEventTypes": [], "riskEventTypes_v2": [], "resourceDisplayName": "Office 365 SharePoint Online", "resourceId": "$$$$$$$", "resourceTenantId": "$$$$$$$$$", "homeTenantId": "#########", "authenticationMethodsUsed": [], "authenticationRequirement": "singleFactorAuthentication", "alternateSignInName": "", "signInIdentifier": "", "signInIdentifierType": null, "servicePrincipalName": null, "signInEventTypes": ["interactiveUser"], "servicePrincipalId": "", "userType": "guest", "flaggedForReview": false, "isTenantRestricted": false, "autonomousSystemNumber": 45609, "crossTenantAccessType": "b2bCollaboration", "servicePrincipalCredentialKeyId": null, "servicePrincipalCredentialThumbprint": "", "mfaDetail": null, "status": { "errorCode": 0, "failureReason": "Other.", "additionalDetails": null }, "deviceDetail": { "deviceId": "", "displayName": "", "operatingSystem": "Windows 10", "browser": "Chrome 92.0.4515", "isCompliant": false, "isManaged": false, "trustType": "" }, "location": { "city": "Kallimandayam", "state": "Tamil Nadu", "countryOrRegion": "IN", "geoCoordinates": { "altitude": null, "latitude": "", "longitude": "" }}, "appliedConditionalAccessPolicies": [], "authenticationProcessingDetails": [{ "key": "Login Hint Present", "value": "True" }, { "key": "User certificate authentication level", "value": "singleFactorAuthentication" } ], "networkLocationDetails": [], "authenticationDetails": [], "authenticationRequirementPolicies": [], "sessionLifetimePolicies": [], "privateLinkDetails": { "policyId": "", "policyName": "", "resourceId": "", "policyTenantId": "" } }
原因分析与解释
其实这种情况本质是跨租户身份上下文的差异导致的,咱们结合你的场景和API响应来拆解:
跨租户协作的身份映射逻辑:
从你的示例响应里能看到crossTenantAccessType": "b2bCollaboration",这说明这条登录记录是用户从自己的主租户(homeTenantId对应的租户)访问另一个租户的资源(resourceTenantId对应的租户)。在资源租户的视角下,这个用户属于外部协作用户,所以会被标记为userType": "guest"——哪怕这个用户在自己的主租户里是内部用户,到了其他租户的资源上下文里,身份就会切换成来宾。Azure AD门户的租户上下文残留:
你提到的登录门户时跳到之前的租户,其实是当前登录会话的租户上下文切换到了那个资源租户。这时候门户是在资源租户的环境下加载的,所以它识别你为来宾用户,因为你不是这个租户的内部成员,只是通过B2B协作进来的外部用户。SharePoint场景的特殊点:
你的示例里正好是SharePoint Online的登录记录(appDisplayName": "SharePoint Online Web Client Extensibility")。SharePoint的跨租户站点共享是完全基于Azure AD B2B机制的:当你的内部用户访问其他租户共享的SharePoint站点时,资源租户(也就是共享站点所属的租户)会把这个用户识别为来宾,对应的登录审计记录自然就会标记userType为guest。这是SharePoint跨租户协作的正常身份呈现逻辑。
简单来说,userType的取值是**相对于当前登录记录所属的租户(也就是resourceTenantId)**而言的,不是绝对的用户属性——同一个用户在不同租户上下文里,身份标签会不一样。
内容的提问来源于stack exchange,提问作者Maerona_Wynn

