You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure API Management中OAuth2.0客户端凭证授权配置问题

配置Azure API Management调用Azure AD B2C用户列表时的授权问题

我正尝试配置一个API,通过Azure API Management获取Azure AD B2C目录中的用户列表。在Postman中,我可通过以下请求获取Bearer令牌,并用其调用https://graph.microsoft.com/v1.0/users端点:

POST /{TenantId}/oauth2/v2.0/token HTTP/1.1
Host: login.microsoftonline.com
Content-Type: application/x-www-form-urlencoded
Content-Length: 182

grant_type=client_credentials&client_id={ClientId}&client_secret={ClientSecret}&scope=https%3A%2F%2Fgraph.microsoft.com%2F.default

但在Azure API Management的Authorizations配置中,出现以下错误:

Failed to acquire access token for service using client credentials flow: IdentityProvider=oauth2. Details: {"error":"invalid_request","error_description":"AADSTS90014: The required field 'scope' is missing from the credential. Ensure that you have all the necessary parameters for the login request.}

这是因为我未配置scope属性,但Client Credentials授权类型中没有该配置项。请问scope应在哪里定义?是在应用注册中吗?

更新1:
取得小进展。改用Azure Active Directory V1版本而非OAuth2.0身份提供商,可获取授权令牌,但通过get-authorization-context策略测试时,返回的访问令牌发行方错误,并非指定租户而是common租户。

更新2:
问题已解决。再次尝试时仅移除了resource中的/.default,即可正常工作,暂不清楚此前失败原因。

内容的提问来源于stack exchange,提问作者Kiran Ramaswamy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 11:29:58