使用Azure Tasks(预览版)启动VM时遇InvalidAuthenticationTokenTenant错误
解决Azure Tasks(预览版)启动VM任务的InvalidAuthenticationTokenTenant错误
在Azure Tasks(预览版)中创建启动虚拟机(VM)的任务,任务创建成功但执行失败,返回InvalidAuthenticationTokenTenant错误,错误详情如下:
{ "error": { "code": "InvalidAuthenticationTokenTenant", "message": "The access token is from the wrong issuer 'https://sts.windows.net/tokennumbers/'. It must match the tenant 'https://sts.windows.net/tokennumbers/' associated with this subscription. Please use the authority (URL) 'https://login.windows.net/tokennumbers' to get the token. Note, if the subscription is transferred to another tenant there is no impact to the services, but information about new tenant could take time to propagate (up to an hour). If you just transferred your subscription and see this error message, please try back later." } }
同时在Logic Apps设计器中运行相同操作时,返回401未授权错误。
错误原因
这个问题核心是身份令牌的租户与VM所属订阅的租户不匹配,常见触发场景:
- 订阅近期被转移到新租户,Azure后台的租户信息还没完成同步(最长可能需要1小时)
- 创建任务时用的身份(托管标识、服务主体)属于错误的租户
- 获取身份令牌时用的授权端点(authority URL)和订阅租户不匹配
解决步骤
- 等待租户同步(针对刚转移订阅的情况):如果是最近刚把订阅转到新租户,先等1小时再重试任务,让Azure完成租户信息的同步更新。
- 检查任务关联的身份租户:
- 查看Azure Tasks中任务绑定的身份(托管标识或服务主体),确认它的所属租户和VM所在订阅的租户完全一致。
- 如果用的是服务主体,确保创建时选的是订阅对应的租户,且获取令牌的授权端点是
https://login.windows.net/<目标租户ID>。
- 重新配置Logic Apps的连接:
- 在Logic Apps设计器里删掉当前和Azure VM服务的连接。
- 重新创建连接,选择和VM订阅匹配的租户下的身份(个人账户或服务主体),保证连接使用的令牌来自正确租户。
- 验证权限配置:确认使用的身份拥有VM所在资源组的
Microsoft.Compute/virtualMachines/start/action权限,避免因权限不足叠加租户不匹配问题导致401错误。
内容的提问来源于stack exchange,提问作者user16090651
相关产品推荐
相关产品推荐

