You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于Graph API无法获取Microsoft安全评分平均对比分数的技术咨询

关于Microsoft Secure Scores API获取平均对比分数的问题

从2021年8月7日开始,我调用https://graph.microsoft.com/beta/security/secureScores这个REST API时,无法获取到有效的平均对比分数(Average Comparative Scores),返回的所有相关字段值都是0。以下是截取的响应示例:

{
  "id": "$$$$$$$$$$$$$$",
  "azureTenantId": "$$$$$$$$$$$",
  "activeUserCount": 22,
  "createdDateTime": "2021-09-08T00:00:00Z",
  "currentScore": 27.96,
  "enabledServices": [ "HasProject", "HasVisio", "HasAADBasic", "HasTeams" ],
  "licensedUserCount": 250,
  "maxScore": 79,
  "vendorInformation": {
    "provider": "SecureScore",
    "providerVersion": null,
    "subProvider": null,
    "vendor": "Microsoft"
  },
  "averageComparativeScores": [
    {
      "basis": "AllTenants",
      "averageScore": 0,
      "deviceScoreMax": 0,
      "appsScoreMax": 0,
      "infrastructureScoreMax": 0,
      "dataScoreMax": 0,
      "identityScore": 0,
      "deviceScore": 0,
      "appsScore": 0,
      "identityScoreMax": 0,
      "infrastructureScore": 0,
      "dataScore": 0
    },
    {
      "basis": "IndustryTypes",
      "averageScore": 0,
      "deviceScoreMax": 0,
      "appsScoreMax": 0,
      "infrastructureScoreMax": 0,
      "dataScoreMax": 0,
      "identityScore": 0,
      "deviceScore": 0,
      "appsScore": 0,
      "identityScoreMax": 0,
      "infrastructureScore": 0,
      "dataScore": 0
    },
    {
      "basis": "TotalSeats",
      "averageScore": 0,
      "deviceScoreMax": 0,
      "appsScoreMax": 0,
      "infrastructureScoreMax": 0,
      "dataScoreMax": 0,
      "identityScore": 0,
      "deviceScore": 0,
      "appsScore": 0,
      "identityScoreMax": 0,
      "infrastructureScore": 0,
      "dataScore": 0
    }
  ],
  "controlScores": [
    {
      "controlCategory": "Identity",
      "controlName": "AdminMFAV2",
      "description": "Requiring multi-factor authentication (MFA) for all administrative roles makes it harder for attackers to access accounts. Administrative roles have higher permissions than typical users. If any of those accounts are compromised, critical devices and data is open to attack. ",
      "score": 6.96,
      "implementationStatus": "You have 16 out of 23 users with administrative roles registered and protected with MFA.",
      "controlState": "active",
      "lastSynced": "2021-09-08T00:00:00Z",
      "IsApplicable": "true",
      "count": "7",
      "total": "23",
      "scoreInPercentage": 69.56
    }
  ]
}

想请教一下,这是API存在漏洞,还是我需要改用其他REST API来获取这些对比分数?


我的解答:

首先,这不太可能是API漏洞,更大概率是Beta版本API的迭代变化或者数据生成逻辑的调整,给你几个排查方向和解决方案:

  • Beta API的不确定性:你用的是Beta版本的Graph API,这个版本本身就是微软用于功能预览的,随时可能调整字段返回逻辑、甚至移除部分功能。averageComparativeScores字段返回全0,有可能是微软对这个字段的计算规则做了变更,或者暂时停止了该字段的数据源同步。

  • 切换到稳定版API尝试:建议你换成v1.0版本的/security/secureScores API试试,稳定版的API行为更可靠,不会轻易变更。不过要注意v1.0的响应结构可能和Beta版有差异,需要确认字段是否存在或者名称是否有变化。

  • 检查租户数据条件:另外,微软生成对比分数需要足够的基准数据,如果你的租户规模较小(比如活跃用户数少、服务启用时间短),或者所在行业/用户量级的基准样本不足,也可能导致返回全0的对比分数。你可以核对下自己租户的相关数据是否满足生成对比基准的要求。

  • 确认官方文档更新:可以查看Graph API的官方文档,确认averageComparativeScores字段是否还在当前Beta版本中支持,或者是否有新的替代字段/API端点。

如果以上方法都无法解决,建议你通过微软的官方支持渠道提交工单,让技术团队帮忙排查具体原因。


内容的提问来源于stack exchange,提问作者Maerona_Wynn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 10:22:46