You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

用户托管标识已配置仍报错:ManagedIdentityCredential身份未关联资源

问题描述

为实现通过Azure Python SDK免手动登录执行VM启停、解除分配等操作,已完成以下配置:

  • 创建Ubuntu VM及用户分配托管标识
  • 为该标识分配Virtual-Machine Contributor角色
  • 通过Azure门户将标识关联至目标VM

但执行az logout后运行代码报错,且登录状态下错误仍存在;尝试使用DefaultAzureCredentials也无法解决。核心错误为:

ManagedIdentityCredential.get_token failed: ManagedIdentityCredential authentication unavailable. The requested identity has not been assigned to this resource

完整错误栈
ImdsCredential.get_token failed: ManagedIdentityCredential authentication unavailable. The requested identity has not been assigned to this resource.ManagedIdentityCredential.get_token failed: ManagedIdentityCredential authentication unavailable. The requested identity has not been assigned to this resource.
Traceback (most recent call last):
File "/home/sehajvm/.local/lib/python3.10/site-packages/azure/identity/_credentials/imds.py", line 91, in _request_token token = self._client.request_token(*scopes, headers={"Metadata": "true"})
File "/home/sehajvm/.local/lib/python3.10/site-packages/azure/identity/_internal/managed_identity_client.py", line 120, in request_token token = self._process_response(response, request_time)
File "/home/sehajvm/.local/lib/python3.10/site-packages/azure/identity/_internal/managed_identity_client.py", line 61, in _process_response raise ClientAuthenticationError( azure.core.exceptions.ClientAuthenticationError: Unexpected response "{'error': 'invalid_request', 'error_description': 'Identity not found'}"
Content: {"error":"invalid_request","error_description":"Identity not found"}
执行代码示例
import os 
from azure.mgmt.compute import ComputeManagementClient 
from azure.identity import ManagedIdentityCredential 

# Set subscription and resource group variables 
subscription_id = '' 
resource_group = '' 
client_id = '' 

# Set virtual machine name and new power state 
vm_name = 'additionalvm' 
new_power_state = 'begin_deallocate'  

# Authenticate with Azure using a managed identity 
credentials = ManagedIdentityCredential(client_id=client_id) 

# Create a ComputeManagementClient object 
compute_client = ComputeManagementClient(credentials, subscription_id) 

# Get the virtual machine 
vm = compute_client.virtual_machines.get(resource_group, vm_name) 

# Stop or start the virtual machine 
if new_power_state == 'begin_deallocate': 
   async_vm_stop = compute_client.virtual_machines.begin_deallocate(resource_group, vm_name)
   async_vm_stop.wait() 
   print(f"Virtual machine {vm_name} has been stopped.") 
elif new_power_state == 'begin_start': 
   async_vm_start = compute_client.virtual_machines.begin_start(resource_group, vm_name)
   async_vm_start.wait() 
   print(f"Virtual machine {vm_name} has been started.") 
else: 
   print(f"Invalid power state: {new_power_state}")
解决方案
  • 验证标识与VM的关联状态:登录Azure门户,进入目标VM的「标识」->「用户分配」标签,确认代码中使用的client_id对应的标识已在列表中,状态为已分配。若未关联,点击「添加」选择目标标识并保存,等待5-10分钟让配置生效。
  • 确认Client ID正确性:确保代码中的client_id是用户分配托管标识的客户端ID(可在标识的「概述」页面获取),而非资源ID或对象ID。
  • 检查VM内部IMDS服务可用性:登录Ubuntu VM,执行以下命令测试托管标识服务:
    curl -H Metadata:true "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2021-02-01&resource=https://management.azure.com/"
    
    若返回「Identity not found」,重启VM刷新配置。
  • 核对角色分配作用域:进入用户分配标识的「访问控制(IAM)」->「角色分配」,确认Virtual-Machine Contributor角色的作用域覆盖目标VM所在的资源组或VM本身,避免仅将角色分配到标识自身。
  • 优化DefaultAzureCredential使用(可选):若改用DefaultAzureCredential,可设置环境变量强制优先使用托管标识,避免本地CLI缓存干扰:
    import os
    os.environ["AZURE_IDENTITY_DISABLE_CLI"] = "true"
    from azure.identity import DefaultAzureCredential
    credentials = DefaultAzureCredential(client_id=client_id)
    

内容的提问来源于stack exchange,提问作者Sehajpreet Kaur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 16:22:50