如何通过Microsoft Graph API获取从AWS导入至Azure的角色ID并为Azure AD组分配该角色
Got it, let's tackle this problem step by step. The core issue here is locating the ID of the AWS role you imported into Azure AD—this ID is required to complete the app role assignment via Microsoft Graph API. Here's how you can automate the entire process:
Step 1: Get the Object ID of Your AWS Enterprise Application (resourceId)
The AWS roles you imported are tied to an enterprise application registered in your Azure AD. You'll first need this app's service principal ID (this becomes the resourceId in your assignment request body).
To fetch this via Graph API:
GET https://graph.microsoft.com/v1.0/servicePrincipals?$filter=displayName eq 'AWS Account: [your-aws-account-id]'
Replace [your-aws-account-id] with your actual AWS account number. The id field in the response is your resourceId.
If you prefer using the Azure Portal: Navigate to Azure Active Directory > Enterprise Applications, search for your AWS account app, then copy the Object ID from the overview page.
Step 2: Retrieve the ID of the Imported AWS Role (id-of-role)
With the AWS app's service principal ID in hand, fetch all its associated appRoles—these are the roles you imported from AWS:
GET https://graph.microsoft.com/v1.0/servicePrincipals/{service-principal-id}/appRoles
In the response, look for the appRole entry where the displayName matches your target AWS role name (note: it might show as the full ARN like arn:aws:iam::[account-id]:role/[role-name]). The id field of this entry is the id-of-role you need for the assignment.
Step 3: Assign the Role to Your Azure AD Group
Now use the appRoleAssignments API to link the role to your group. Here's the complete request:
API Request
POST https://graph.microsoft.com/v1.0/groups/{group-id}/appRoleAssignments Content-Type: application/json
Request Body
{ "id": "your-found-approle-id", "principalId": "your-azure-ad-group-object-id", "resourceId": "your-aws-service-principal-id" }
Key Notes
- Permissions: Make sure the identity (user or service principal) making these API calls has the right permissions. For delegated access, you'll need
Directory.Read.AllandAppRoleAssignment.ReadWrite.All. For application-level access, useApplication.Read.AllandAppRoleAssignment.ReadWrite.All. - Verification: After sending the assignment request, you can confirm success by calling
GET https://graph.microsoft.com/v1.0/groups/{group-id}/appRoleAssignments—you should see your new assignment in the response.
内容的提问来源于stack exchange,提问作者hashim vayalar

