如何通过PowerShell脚本为AAD应用添加作用域与客户端应用
为AAD应用添加作用域与客户端应用的PowerShell脚本更新方案
一、添加自定义API作用域
如果需要让你的AAD应用作为API提供自定义作用域供其他应用调用,需先定义API的唯一标识符,再创建作用域并关联到应用。更新后的创建脚本示例:
# 定义API唯一标识符(通常使用域名+应用标识的格式) $apiIdentifierUri = "https://contoso.com/ui-api" # 创建自定义作用域 $customScope = New-AzADAppPermissionScope -DisplayName "读取用户基础数据" ` -Id (New-Guid) ` -IsEnabled $true ` -Type "User" ` -Value "user.basic.read" ` -AdminConsentDisplayName "允许读取用户基础数据" ` -AdminConsentDescription "授权应用读取用户的基础信息" # 创建AAD应用并关联API标识符与自定义作用域 $uiApp = New-AzADApplication -DisplayName $uiAppDisplayName ` -AvailableToOtherTenants $false ` -ReplyUrls $replyUrls ` -RequiredResourceAccess $requiredResourceAccess ` -IdentifierUris $apiIdentifierUri ` -ApiPermissionScopes $customScope
二、配置允许访问的客户端应用
要指定哪些客户端应用可以访问你的AAD应用API,可在应用创建完成后,通过权限分配命令添加授权:
# 目标客户端应用的对象ID(可通过Azure门户或Get-AzADApplication命令获取) $clientAppObjectId = "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" # 使用之前创建的自定义作用域ID $scopeId = $customScope.Id # 为客户端应用分配访问权限 New-AzADAppRoleAssignment -ObjectId $clientAppObjectId ` -PrincipalId $clientAppObjectId ` -ResourceId $uiApp.Id ` -Id $scopeId
三、补充:添加第三方API作用域(如Microsoft Graph)
如果你的应用需要作为客户端访问公共API(比如Microsoft Graph)的权限,需完善$requiredResourceAccess参数的配置,示例如下:
# Microsoft Graph的固定资源ID $graphResourceId = "00000003-0000-0000-c000-000000000000" # 定义User.Read权限的资源访问对象 $graphUserReadAccess = New-Object Microsoft.Azure.PowerShell.Cmdlets.Resources.MSGraph.Models.ApiV10.MicrosoftGraphResourceAccess $graphUserReadAccess.Id = "e1fe6dd8-ba31-4d61-89e7-88639da4683d" # User.Read权限ID $graphUserReadAccess.Type = "Scope" # 组装所需的资源访问配置 $requiredGraphAccess = New-Object Microsoft.Azure.PowerShell.Cmdlets.Resources.MSGraph.Models.ApiV10.MicrosoftGraphRequiredResourceAccess $requiredGraphAccess.ResourceAppId = $graphResourceId $requiredGraphAccess.ResourceAccess = @($graphUserReadAccess) # 赋值给参数后创建应用 $requiredResourceAccess = @($requiredGraphAccess) $uiApp = New-AzADApplication -DisplayName $uiAppDisplayName ` -AvailableToOtherTenants $false ` -ReplyUrls $replyUrls ` -RequiredResourceAccess $requiredResourceAccess
注意事项
- 各类ID参数(如权限ID、资源ID)可通过Azure门户或
Get-AzADServicePrincipal等命令查询获取 - 若要更新已存在的AAD应用,将
New-AzADApplication替换为Set-AzADApplication,并指定应用的-ObjectId或-ApplicationId参数
内容的提问来源于stack exchange,提问作者user989988
相关产品推荐
相关产品推荐

