You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell脚本为AAD应用添加作用域与客户端应用

为AAD应用添加作用域与客户端应用的PowerShell脚本更新方案

一、添加自定义API作用域

如果需要让你的AAD应用作为API提供自定义作用域供其他应用调用,需先定义API的唯一标识符,再创建作用域并关联到应用。更新后的创建脚本示例:

# 定义API唯一标识符(通常使用域名+应用标识的格式)
$apiIdentifierUri = "https://contoso.com/ui-api"

# 创建自定义作用域
$customScope = New-AzADAppPermissionScope -DisplayName "读取用户基础数据" `
                                          -Id (New-Guid) `
                                          -IsEnabled $true `
                                          -Type "User" `
                                          -Value "user.basic.read" `
                                          -AdminConsentDisplayName "允许读取用户基础数据" `
                                          -AdminConsentDescription "授权应用读取用户的基础信息"

# 创建AAD应用并关联API标识符与自定义作用域
$uiApp = New-AzADApplication -DisplayName $uiAppDisplayName `
                             -AvailableToOtherTenants $false `
                             -ReplyUrls $replyUrls `
                             -RequiredResourceAccess $requiredResourceAccess `
                             -IdentifierUris $apiIdentifierUri `
                             -ApiPermissionScopes $customScope

二、配置允许访问的客户端应用

要指定哪些客户端应用可以访问你的AAD应用API,可在应用创建完成后,通过权限分配命令添加授权:

# 目标客户端应用的对象ID(可通过Azure门户或Get-AzADApplication命令获取)
$clientAppObjectId = "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"

# 使用之前创建的自定义作用域ID
$scopeId = $customScope.Id

# 为客户端应用分配访问权限
New-AzADAppRoleAssignment -ObjectId $clientAppObjectId `
                          -PrincipalId $clientAppObjectId `
                          -ResourceId $uiApp.Id `
                          -Id $scopeId

三、补充:添加第三方API作用域(如Microsoft Graph)

如果你的应用需要作为客户端访问公共API(比如Microsoft Graph)的权限,需完善$requiredResourceAccess参数的配置,示例如下:

# Microsoft Graph的固定资源ID
$graphResourceId = "00000003-0000-0000-c000-000000000000"

# 定义User.Read权限的资源访问对象
$graphUserReadAccess = New-Object Microsoft.Azure.PowerShell.Cmdlets.Resources.MSGraph.Models.ApiV10.MicrosoftGraphResourceAccess
$graphUserReadAccess.Id = "e1fe6dd8-ba31-4d61-89e7-88639da4683d" # User.Read权限ID
$graphUserReadAccess.Type = "Scope"

# 组装所需的资源访问配置
$requiredGraphAccess = New-Object Microsoft.Azure.PowerShell.Cmdlets.Resources.MSGraph.Models.ApiV10.MicrosoftGraphRequiredResourceAccess
$requiredGraphAccess.ResourceAppId = $graphResourceId
$requiredGraphAccess.ResourceAccess = @($graphUserReadAccess)

# 赋值给参数后创建应用
$requiredResourceAccess = @($requiredGraphAccess)
$uiApp = New-AzADApplication -DisplayName $uiAppDisplayName `
                             -AvailableToOtherTenants $false `
                             -ReplyUrls $replyUrls `
                             -RequiredResourceAccess $requiredResourceAccess

注意事项

  • 各类ID参数(如权限ID、资源ID)可通过Azure门户或Get-AzADServicePrincipal等命令查询获取
  • 若要更新已存在的AAD应用,将New-AzADApplication替换为Set-AzADApplication,并指定应用的-ObjectId或-ApplicationId参数

内容的提问来源于stack exchange,提问作者user989988

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 03:05:27