You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform创建AzureAD应用时触发AADSTS650052错误求助

解决AADSTS650052错误:Terraform创建的多租户API服务主体缺失问题

AADSTS650052错误的核心原因是:企业用户登录时,其所在租户中没有你API应用对应的服务主体。手动创建应用时,Azure会自动触发管理员同意流程来创建该服务主体,但Terraform创建的应用因缺少关键配置,导致流程未正常触发。以下是针对性解决方案:

1. 使用验证过的自定义域名作为API的标识符URI

避免使用租户默认的.onmicrosoft.com域名作为API的identifier_uris前缀——其他企业租户无法将该域名关联到自身的服务主体。改用Azure AD中已验证的自定义域名,保持URI固定(无需随机UUID):

resource "azuread_application" "server" {
  # ... 其他配置
  identifier_uris = [ "https://auth.yourcompany.com/productname-api" ]
  # ... 其他配置
}

2. 显式配置API权限的同意设置

在API应用的OAuth2权限范围中,显式启用用户/管理员同意选项,确保Azure能触发对应的审批流程:

resource "azuread_application" "server" {
  # ... 其他配置
  api {
    # ... 其他配置
    oauth2_permission_scope {
      admin_consent_description = "Allow ProductName to access a user's name and email address."
      admin_consent_display_name = "Access user name and email address"
      enabled = true
      id = random_uuid.server_api_scope_id.result
      type = "User"
      user_consent_description = "Allow ProductName to access your name and email address."
      user_consent_display_name = "Access your name and email address"
      value = "access_as_user"
      user_consent_enabled = true  # 允许用户自行同意,若需强制管理员审批则设为false
      admin_consent_enabled = true # 显式启用管理员同意(默认值,但显式设置更明确)
    }
  }
  # ... 其他配置
}

3. 标记API服务主体为企业应用

在API的服务主体资源中添加特性标签,确保多租户场景下的兼容性:

resource "azuread_service_principal" "server" {
  application_id               = azuread_application.server.application_id
  app_role_assignment_required = false
  owners                       = [data.azuread_client_config.current.object_id]
  feature_tags {
    enterprise = true
    gallery    = false
  }
}

4. 触发企业租户管理员同意流程

对于企业用户所在的租户,需要管理员执行同意操作来创建API服务主体。构造以下URL并提供给企业管理员访问:

https://login.microsoftonline.com/{企业租户ID}/adminconsent?client_id={客户端应用ID}&state=12345&redirect_uri={客户端回调URL}

替换占位符为实际值,管理员同意后,API的服务主体会自动创建在其租户中,错误即可解决。

5. 验证权限关联正确性

通过Terraform输出API权限的ID,手动确认客户端应用的权限请求是否关联正确:

output "server_api_scope_id" {
  value = random_uuid.server_api_scope_id.result
}

部署后查看输出值,对比Azure门户中API应用权限的ID,确保两者一致。


内容的提问来源于stack exchange,提问作者Peter Morris

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 21:17:56