You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Function创建Exchange Online邮箱别名遇证书认证问题求助

问题与解决方案

需求背景

需要通过API调用创建邮箱别名,发现Microsoft Graph暂不支持该功能,计划采用PowerShell编写Azure Function实现,直至有替代API可用。

已实现代码

Azure Function PowerShell代码

using namespace System.Net

# Input bindings are passed in via param block.
param($Request, $TriggerMetadata)

Install-Module ExchangeOnlineManagement -Force
Connect-ExchangeOnline -CertificateThumbPrint "{thumbprint}" -AppID "{appid}" -Organization "org.onmicrosoft.com"

# Write to the Azure Functions log stream.
Write-Host "PowerShell HTTP trigger function processed a request."

# Interact with query parameters or the body of the request.
$name = $Request.Query.Name
if (-not $name) {
    $name = $Request.Body.Name
}

$user = $Request.Query.User
if (-not $user) {
    $user = $Request.Body.User
}

Set-Mailbox $user -EmailAddresses @{add="{"+$name+"@yourorg.com"}

$body = "This HTTP triggered function executed successfully. Pass a name in the query string or in the request body for a personalized response."

if ($name) {
    $body = "Hello, $user. This HTTP triggered function executed successfully."
}

# Associate values to output bindings by calling 'Push-OutputBinding'.
Push-OutputBinding -Name Response -Value ([HttpResponseContext]@{
    StatusCode = [HttpStatusCode]::OK
    Body = $body
})

requirements.psd1配置文件

# This file enables modules to be automatically managed by the Functions service.
# See https://aka.ms/functionsmanageddependency for additional information.
#
@{
    # For latest supported version, go to 'https://www.powershellgallery.com/packages/Az'. 
    # To use the Az module in your function app, please uncomment the line below.
    # 'Az' = '6.*'
     'ExchangeOnlineManagment' = '3.*'
}

当前遇到的问题

使用证书指纹的应用注册无法正常连接Exchange Online,执行连接命令:

Connect-ExchangeOnline -CertificateThumbPrint "{thumbprint}" -AppID "{appid}" -Organization "org.onmicrosoft.com"

时出现错误:[Error] EXCEPTION: No certificate found for the given CertificateThumbPrint,已完成应用注册并配置证书及对应指纹。

解决方案

一、解决证书认证失败问题

  1. 移除手动安装模块命令:删除代码中的Install-Module ExchangeOnlineManagement -Force,requirements.psd1已配置自动管理模块,手动安装会导致冲突。
  2. 确认证书部署位置:
    • Windows计划:将证书上传至Function App的「SSL证书」→「私有证书」,确保函数拥有证书私钥的访问权限;或通过Azure Key Vault挂载证书,给函数分配Key Vault的「证书用户」权限。
    • Linux计划:将证书放置在函数可访问的路径,或通过Key Vault引用证书,配置函数的访问权限。
  3. 校验证书指纹格式:确保指纹是纯十六进制字符串,无空格、分隔符,大小写一致。
  4. 改用证书对象连接:通过Key Vault获取证书对象传入命令,避免指纹匹配问题:
    $cert = Get-AzKeyVaultCertificate -VaultName "你的KeyVault名称" -Name "证书名称"
    Connect-ExchangeOnline -Certificate $cert -AppID "{appid}" -Organization "org.onmicrosoft.com"
    
  5. 验证应用权限:确认应用注册已添加Exchange Online的「Application权限」(如MailboxSettings.ReadWrite),并完成管理员同意授权。

二、更优的API方案:使用Microsoft Graph API创建邮箱别名

目前Microsoft Graph已支持通过更新用户的proxyAddresses属性添加别名,无需依赖PowerShell模块:

  1. 操作步骤:
    • 先获取用户现有别名:发送GET https://graph.microsoft.com/v1.0/users/{用户ID或UPN}请求,提取返回结果中的proxyAddresses数组。
    • 将新别名(前缀为smtp:)添加到数组中(需保留原有主地址SMTP:和其他别名),再发送PATCH请求更新:
      PATCH https://graph.microsoft.com/v1.0/users/{用户ID或UPN}
      Content-Type: application/json
      
      {
        "proxyAddresses": [
          "SMTP:primary@yourorg.com",
          "smtp:existing-alias@yourorg.com",
          "smtp:new-alias@yourorg.com"
        ]
      }
      
  2. 权限配置:应用注册添加User.ReadWrite.All的Application权限,并完成管理员同意授权。

内容的提问来源于stack exchange,提问作者Eric

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 00:02:54