Azure Automation中用Reader权限UMI执行Get-AzADUser报错权限不足
Azure Automation Runbook调用Get-AzADUser权限不足问题排查思路
问题场景
- 配置了Azure Automation账户,其中PowerShell Runbook代码如下:
$AzureContext = (Connect-AzAccount -Identity).context Get-AzADUser -UserPrincipalName '<me@mydomain.com>'
- 在同订阅、同资源组下创建了用户分配托管身份(UMI),并为其分配资源组范围的Reader角色
- 已通过
Automation账户 | 标识 -> 用户分配 -> +添加路径将UMI绑定到Automation账户
错误现象
运行Runbook时,执行Get-AzADUser抛出权限不足错误:
[Authorization_RequestDenied] : Insufficient privileges to complete the operation.
作业流详情:
Az.MSGraph.internal\Get-AzADUser : Insufficient privileges to complete the operation. At C:\Modules\Global\Az.Resources\MSGraph.Autorest\custom\Get-AzADUser.ps1:199 char:9 + Az.MSGraph.internal\Get-AzADUser @PSBoundParameters + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : InvalidOperation: ({ ConsistencyLe...= , Expand = }: <>f__AnonymousType5`7) [Get-AzADUser_List], Exception + FullyQualifiedErrorId : Authorization_RequestDenied,Microsoft.Azure.PowerShell.Cmdlets.Resources.MSGraph.Cmdlets.GetAzADUser_List
解决思路
- 权限类型不匹配:资源组范围的Reader角色仅能访问该资源组内的Azure资源(如VM、存储等),但
Get-AzADUser是操作Azure AD目录对象的请求,需要的是Azure AD目录权限,而非Azure资源权限。 - 为UMI分配Azure AD目录权限:
- 登录Azure门户,进入Azure Active Directory -> 企业应用程序,找到你的用户分配托管身份(UMI会以企业应用形式存在)
- 进入该应用的权限 -> 添加权限 -> 选择Microsoft Graph -> 应用权限
- 搜索并添加
User.Read.All或User.ReadBasic.All权限(仅读取用户基础信息选User.ReadBasic.All即可) - 添加后点击授予管理员同意(需Azure AD全局管理员或权限管理员权限)
- 指定Runbook使用UMI:默认
Connect-AzAccount -Identity会优先使用系统分配身份(若存在),需修改代码指定用户分配身份:
$UMIClientId = "<你的UMI客户端ID>" $AzureContext = (Connect-AzAccount -Identity -AccountId $UMIClientId).context Get-AzADUser -UserPrincipalName '<me@mydomain.com>'
- 更新Az模块版本:确保Automation账户中的Az.Resources模块为最新版本,旧版本可能存在权限调用兼容性问题
- 等待权限生效:权限授予后可能存在10-15分钟的延迟,之后再重新测试Runbook
内容的提问来源于stack exchange,提问作者Jug of Bugs
相关产品推荐
相关产品推荐

