You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Automation中用Reader权限UMI执行Get-AzADUser报错权限不足

Azure Automation Runbook调用Get-AzADUser权限不足问题排查思路

问题场景

  • 配置了Azure Automation账户,其中PowerShell Runbook代码如下:
$AzureContext = (Connect-AzAccount -Identity).context
Get-AzADUser -UserPrincipalName '<me@mydomain.com>'
  • 在同订阅、同资源组下创建了用户分配托管身份(UMI),并为其分配资源组范围的Reader角色
  • 已通过Automation账户 | 标识 -> 用户分配 -> +添加路径将UMI绑定到Automation账户

错误现象

运行Runbook时,执行Get-AzADUser抛出权限不足错误:

[Authorization_RequestDenied] : Insufficient privileges to complete the operation.

作业流详情:

Az.MSGraph.internal\Get-AzADUser : 
Insufficient privileges to complete the operation. At 
C:\Modules\Global\Az.Resources\MSGraph.Autorest\custom\Get-AzADUser.ps1:199 char:9 + Az.MSGraph.internal\Get-AzADUser 
@PSBoundParameters + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
+ CategoryInfo : InvalidOperation: ({ ConsistencyLe...= , Expand = }: 
<>f__AnonymousType5`7) [Get-AzADUser_List], Exception + 
FullyQualifiedErrorId : Authorization_RequestDenied,Microsoft.Azure.PowerShell.Cmdlets.Resources.MSGraph.Cmdlets.GetAzADUser_List

解决思路

  • 权限类型不匹配:资源组范围的Reader角色仅能访问该资源组内的Azure资源(如VM、存储等),但Get-AzADUser是操作Azure AD目录对象的请求,需要的是Azure AD目录权限,而非Azure资源权限。
  • 为UMI分配Azure AD目录权限:
    1. 登录Azure门户,进入Azure Active Directory -> 企业应用程序,找到你的用户分配托管身份(UMI会以企业应用形式存在)
    2. 进入该应用的权限 -> 添加权限 -> 选择Microsoft Graph -> 应用权限
    3. 搜索并添加User.Read.All或User.ReadBasic.All权限(仅读取用户基础信息选User.ReadBasic.All即可)
    4. 添加后点击授予管理员同意(需Azure AD全局管理员或权限管理员权限)
  • 指定Runbook使用UMI:默认Connect-AzAccount -Identity会优先使用系统分配身份(若存在),需修改代码指定用户分配身份:
$UMIClientId = "<你的UMI客户端ID>"
$AzureContext = (Connect-AzAccount -Identity -AccountId $UMIClientId).context
Get-AzADUser -UserPrincipalName '<me@mydomain.com>'
  • 更新Az模块版本:确保Automation账户中的Az.Resources模块为最新版本,旧版本可能存在权限调用兼容性问题
  • 等待权限生效:权限授予后可能存在10-15分钟的延迟,之后再重新测试Runbook

内容的提问来源于stack exchange,提问作者Jug of Bugs

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 22:55:30