Azure AD中Graph Explorer与Power Automate的用户权限差异问题
核心问题
使用Power Automate调用POST https://graph.microsoft.com/v1.0/invitations接口时返回Unauthorized错误,提示应用权限不足,但同一用户在Graph Explorer中执行相同操作成功,且Power Automate可正常执行GET类Graph请求。
关键原因
1. 权限授予范围不一致
Graph Explorer执行操作时,会通过交互式登录让用户即时同意所需的委托权限(如User.Invite.All);但Power Automate的Microsoft Graph连接可能仅配置了基础只读权限(如User.Read.All),未包含创建外部邀请的权限。即使是同一用户,Power Automate连接的权限集是独立于Graph Explorer的,不会自动同步权限。
2. 身份验证上下文差异
Graph Explorer使用的是用户直接的交互式身份验证,权限实时生效;而Power Automate依赖预先创建的连接缓存权限,若初始创建连接时未申请User.Invite.All权限,后续即使用户在Graph Explorer中同意了该权限,Power Automate的连接也不会自动更新权限范围。
3. 目标权限的特殊性
创建外部用户邀请需要委托权限User.Invite.All(或应用权限User.Invite.All,但此处为用户上下文操作,需委托权限),若Power Automate连接未获取该权限,POST操作必然失败,而GET请求仅需只读权限,因此可正常执行。
解决方案
更新Power Automate的Graph连接权限
- 进入Power Automate后台,打开「数据」>「连接」,找到当前使用的Microsoft Graph连接。
- 删除该连接,重新创建连接:在授权弹窗中,确保勾选
User.Invite.All权限(及其他所需权限),完成用户同意流程。
验证Azure AD中的用户权限
- 登录Azure AD管理中心,进入「企业应用」>「所有应用」,找到「Microsoft Graph」应用。
- 查看「用户和组」下目标用户的权限分配,确认已包含
User.Invite.All权限。
检查Power Automate请求配置
- 确认Power Automate中「Invoke an HTTP request」操作选择的是重新创建的Microsoft Graph连接,而非其他身份验证方式。
内容的提问来源于stack exchange,提问作者David Brunelle

