You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD中Graph Explorer与Power Automate的用户权限差异问题

问题分析与解决方案

核心问题

使用Power Automate调用POST https://graph.microsoft.com/v1.0/invitations接口时返回Unauthorized错误,提示应用权限不足,但同一用户在Graph Explorer中执行相同操作成功,且Power Automate可正常执行GET类Graph请求。

关键原因

1. 权限授予范围不一致

Graph Explorer执行操作时,会通过交互式登录让用户即时同意所需的委托权限(如User.Invite.All);但Power Automate的Microsoft Graph连接可能仅配置了基础只读权限(如User.Read.All),未包含创建外部邀请的权限。即使是同一用户,Power Automate连接的权限集是独立于Graph Explorer的,不会自动同步权限。

2. 身份验证上下文差异

Graph Explorer使用的是用户直接的交互式身份验证,权限实时生效;而Power Automate依赖预先创建的连接缓存权限,若初始创建连接时未申请User.Invite.All权限,后续即使用户在Graph Explorer中同意了该权限,Power Automate的连接也不会自动更新权限范围。

3. 目标权限的特殊性

创建外部用户邀请需要委托权限User.Invite.All(或应用权限User.Invite.All,但此处为用户上下文操作,需委托权限),若Power Automate连接未获取该权限,POST操作必然失败,而GET请求仅需只读权限,因此可正常执行。

解决方案

  1. 更新Power Automate的Graph连接权限

    • 进入Power Automate后台,打开「数据」>「连接」,找到当前使用的Microsoft Graph连接。
    • 删除该连接,重新创建连接:在授权弹窗中,确保勾选User.Invite.All权限(及其他所需权限),完成用户同意流程。
  2. 验证Azure AD中的用户权限

    • 登录Azure AD管理中心,进入「企业应用」>「所有应用」,找到「Microsoft Graph」应用。
    • 查看「用户和组」下目标用户的权限分配,确认已包含User.Invite.All权限。
  3. 检查Power Automate请求配置

    • 确认Power Automate中「Invoke an HTTP request」操作选择的是重新创建的Microsoft Graph连接,而非其他身份验证方式。

内容的提问来源于stack exchange,提问作者David Brunelle

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 14:25:19