You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用本地登录用户凭据通过Azure Communication Service发送邮件?

无需Service Principal使用本地用户凭据调用Azure通信服务发送邮件的解决方案

问题描述

本地使用DefaultAzureCredential结合Azure CLI登录调用Azure通信服务发送邮件时,触发以下认证错误:

Azure.Identity.AuthenticationFailedException: Azure CLI authentication failed due to an unknown error. See the troubleshooting guide for more information. 
ERROR: AADSTS65002: Consent between first party application '04b07795-8ddb-461a-bbee-02f9e1bf7b46' 
and first party resource '632ec9eb-fad7-4cbd-993a-e72973ba2acc' must be configured via preauthorization - applications owned and operated by Microsoft must get approval from the API owner before requesting tokens for that API.

失败的代码示例:

using Azure;
using Azure.Communication.Email;
using Azure.Identity;

var credentials = new DefaultAzureCredential(new DefaultAzureCredentialOptions() { TenantId = "my-tenant-id" });
var client = new EmailClient(new Uri("https://mydomain.communication.azure.com/"), credentials);
var subject = "Welcome to Azure Communication Service Email APIs.";
var htmlContent = "<html><body><h1>Quick send email test</h1><br/><h4>This email message is sent from Azure Communication Service Email.</h4><p>This mail was sent using .NET SDK!!</p></body></html>";
var sender = "DoNotReply@mydomain.com";
var recipient = "user@mydomain.com";

var message = new EmailMessage(sender, recipient, new EmailContent(subject) { Html = htmlContent });
var operation = await client.SendAsync(WaitUntil.Started, message);

使用Service Principal的代码可正常运行:

using Azure;
using Azure.Communication.Email;
using Azure.Identity;

var credentials = new ClientSecretCredential("tenant-id",
    "client-id", "client-secret");
var client = new EmailClient(new Uri("https://mydomain.communication.azure.com/"), credentials);
var subject = "Welcome to Azure Communication Service Email APIs.";
var htmlContent = "<html><body><h1>Quick send email test</h1><br/><h4>This email message is sent from Azure Communication Service Email.</h4><p>This mail was sent using .NET SDK!!</p></body></html>";
var sender = "DoNotReply@mydomain.com";
var recipient = "user@mydomain.com";

var message = new EmailMessage(sender, recipient, new EmailContent(subject) { Html = htmlContent });
var operation = await client.SendAsync(WaitUntil.Started, message);

用户已拥有通信服务资源的Contributor角色,希望找到无需Service Principal的本地用户凭据调用方案。

可行解决方案

1. 使用Visual Studio凭据认证

直接通过Visual Studio登录Azure账号(确保账号具备通信服务的权限),修改代码优先使用Visual Studio凭据:

using Azure;
using Azure.Communication.Email;
using Azure.Identity;

var options = new DefaultAzureCredentialOptions
{
    TenantId = "my-tenant-id",
    ExcludeAzureCliCredential = true, // 排除Azure CLI避免触发预授权错误
    ExcludeInteractiveBrowserCredential = false // 可选,保留浏览器登录作为 fallback
};
var credentials = new DefaultAzureCredential(options);
var client = new EmailClient(new Uri("https://mydomain.communication.azure.com/"), credentials);

// 后续邮件发送逻辑不变
var subject = "Welcome to Azure Communication Service Email APIs.";
var htmlContent = "<html><body><h1>Quick send email test</h1><br/><h4>This email message is sent from Azure Communication Service Email.</h4><p>This mail was sent using .NET SDK!!</p></body></html>";
var sender = "DoNotReply@mydomain.com";
var recipient = "user@mydomain.com";

var message = new EmailMessage(sender, recipient, new EmailContent(subject) { Html = htmlContent });
var operation = await client.SendAsync(WaitUntil.Started, message);

Visual Studio使用的认证应用已被预授权访问通信服务API,不会触发AADSTS65002错误。

2. 使用交互式浏览器凭据认证

跳过Azure CLI,直接通过浏览器引导用户完成登录:

using Azure;
using Azure.Communication.Email;
using Azure.Identity;

var credentials = new InteractiveBrowserCredential(new InteractiveBrowserCredentialOptions
{
    TenantId = "my-tenant-id"
});
var client = new EmailClient(new Uri("https://mydomain.communication.azure.com/"), credentials);

// 后续邮件发送逻辑不变
var subject = "Welcome to Azure Communication Service Email APIs.";
var htmlContent = "<html><body><h1>Quick send email test</h1><br/><h4>This email message is sent from Azure Communication Service Email.</h4><p>This mail was sent using .NET SDK!!</p></body></html>";
var sender = "DoNotReply@mydomain.com";
var recipient = "user@mydomain.com";

var message = new EmailMessage(sender, recipient, new EmailContent(subject) { Html = htmlContent });
var operation = await client.SendAsync(WaitUntil.Started, message);

运行代码时会弹出浏览器窗口,完成Azure账号登录后即可获取有效令牌,无需额外预授权配置。

3. 为Azure CLI应用添加预授权(租户管理员操作)

若必须使用Azure CLI登录,需租户管理员在Azure AD中为Azure CLI应用(客户端ID:04b07795-8ddb-461a-bbee-02f9e1bf7b46)添加通信服务的预授权:

  • 登录Azure AD门户,通过客户端ID搜索并找到Azure CLI应用
  • 进入应用的API权限页面,添加Azure Communication Service的权限(如CommunicationServices.Email.Send)
  • 点击授予管理员同意完成预授权
    完成配置后,本地Azure CLI登录的用户即可正常调用邮件API。

验证要点

确保本地登录的用户拥有Azure通信服务资源的Contributor角色,或更细粒度的Communication Services Email Sender角色(遵循最小权限原则)。

内容的提问来源于stack exchange,提问作者Gaurav Mantri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 17:47:07