You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Microsoft Graph API获取从AWS导入至Azure的角色ID并为Azure AD组分配该角色

Got it, let's tackle this problem step by step. The core issue here is locating the ID of the AWS role you imported into Azure AD—this ID is required to complete the app role assignment via Microsoft Graph API. Here's how you can automate the entire process:

Automate Azure AD Group Assignment to Imported AWS Roles via Microsoft Graph API

Step 1: Get the Object ID of Your AWS Enterprise Application (resourceId)

The AWS roles you imported are tied to an enterprise application registered in your Azure AD. You'll first need this app's service principal ID (this becomes the resourceId in your assignment request body).

To fetch this via Graph API:

GET https://graph.microsoft.com/v1.0/servicePrincipals?$filter=displayName eq 'AWS Account: [your-aws-account-id]'

Replace [your-aws-account-id] with your actual AWS account number. The id field in the response is your resourceId.

If you prefer using the Azure Portal: Navigate to Azure Active Directory > Enterprise Applications, search for your AWS account app, then copy the Object ID from the overview page.

Step 2: Retrieve the ID of the Imported AWS Role (id-of-role)

With the AWS app's service principal ID in hand, fetch all its associated appRoles—these are the roles you imported from AWS:

GET https://graph.microsoft.com/v1.0/servicePrincipals/{service-principal-id}/appRoles

In the response, look for the appRole entry where the displayName matches your target AWS role name (note: it might show as the full ARN like arn:aws:iam::[account-id]:role/[role-name]). The id field of this entry is the id-of-role you need for the assignment.

Step 3: Assign the Role to Your Azure AD Group

Now use the appRoleAssignments API to link the role to your group. Here's the complete request:

API Request

POST https://graph.microsoft.com/v1.0/groups/{group-id}/appRoleAssignments
Content-Type: application/json

Request Body

{
  "id": "your-found-approle-id",
  "principalId": "your-azure-ad-group-object-id",
  "resourceId": "your-aws-service-principal-id"
}

Key Notes

  • Permissions: Make sure the identity (user or service principal) making these API calls has the right permissions. For delegated access, you'll need Directory.Read.All and AppRoleAssignment.ReadWrite.All. For application-level access, use Application.Read.All and AppRoleAssignment.ReadWrite.All.
  • Verification: After sending the assignment request, you can confirm success by calling GET https://graph.microsoft.com/v1.0/groups/{group-id}/appRoleAssignments—you should see your new assignment in the response.

内容的提问来源于stack exchange,提问作者hashim vayalar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 20:33:12