You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C通过Microsoft Graph调用健康检查偶发403 FORBIDDEN错误

偶发403错误:Azure B2C健康检查端点请求异常

自2023年3月6日起,我们所有Azure B2C环境(开发、预发布、生产)的健康检查端点,约20%的请求会返回403(FORBIDDEN)状态码,错误信息为:

Cannot get company information for the tenant, Please check Cloud Id or retry for another tenant.

这导致系统持续触发健康告警。

我们使用带客户端密钥凭证的.NET Microsoft Graph SDK发起所有Azure B2C请求,已验证所有密钥/ID及HTTP请求中的Bearer Token均正确,但同一Bearer Token的请求有时返回200(OK),有时返回403(FORBIDDEN)。

怀疑Azure内部变更导致该偶发问题,且未影响Microsoft Graph其他端点(详见下方统计)。

Microsoft Graph客户端初始化与使用

在Azure App Service的DI容器中将graphClient注册为单例:

var scopes = new[] { "https://graph.microsoft.com/.default" };
var tenantId = appSettings.B2C_GRAPH_TENANT_ID;
var clientId = appSettings.B2C_GRAPH_CLIENT_ID;
var clientSecret = appSettings.B2C_GRAPH_CLIENT_SECRET;
var options = new TokenCredentialOptions { AuthorityHost = AzureAuthorityHosts.AzurePublicCloud };
var clientSecretCredential = new ClientSecretCredential(tenantId, clientId, clientSecret, options);
var graphClient = new GraphServiceClient(clientSecretCredential, scopes);
...

健康检查定期调用端点:

public async Task<bool> IsHealthy(CancellationToken cancellationToken = default)
{
    try
    {
        var serviceHealths = await _graphClient.Admin.ServiceAnnouncement.HealthOverviews
            .Request()
            .GetAsync(cancellationToken);

        return serviceHealths.Single(h => h.Id == _serviceHealthId)
                .Status is ServiceHealthStatus.ServiceOperational;
    }
    catch (Exception)
    {
        return false;
    }
}

Azure B2C客户端权限

Azure B2C客户端权限

HTTP日志(预发布环境403示例)

HTTP请求

RequestUri: 'https://graph.microsoft.com/v1.0/admin/serviceAnnouncement/healthOverviews', Version: 2.0, Content: <null>, Headers:
{
   SdkVersion: Graph-dotnet-2.0.12
   FeatureFlag: 00000047
   Cache-Control: no-store, no-cache
   Authorization: Bearer [TOKEN]
   Accept-Encoding: gzip
}

HTTP响应

StatusCode: 403, ReasonPhrase: 'Forbidden', Version: 1.1, Content: System.Net.Http.DecompressionHandler+GZipDecompressedContent, Headers:
{
   Transfer-Encoding: chunked
   Vary: Accept-Encoding
   Strict-Transport-Security: max-age=31536000
   request-id: XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX
   client-request-id: XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX
   x-ms-ags-diagnostic: {"ServerInfo":{"DataCenter":"West Europe","Slice":"E","Ring":"5","ScaleUnit":"003","RoleInstance":"XXXXXXXXXXXXX"}}
   X-Instance: westeurope/_readvm_3
   X-TimeTaken: 130
   Date: Wed, 08 Mar 2023 10:30:18 GMT
   Content-Type: application/json
   Content: {"error":{"code":"UnknownError","message":"{\"code\":\"forbidden\",\"message\":\"{\\u0022error\\u0022:\\u0022Cannot get company information for the tenant, Please check Cloud Id or retry for another tenant. ActivityId: XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX. Learn more: https://docs.microsoft.com/en-us/graph/api/resources/service-communications-api-overview?view=graph-rest-beta\\\\u0026preserve-view=true.\\u0022}\"}","innerError":{"date":"2023-03-08T10:30:18","request-id":"XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX","client-request-id":"XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX"}}}
}

各端点HTTP状态码统计

HTTP状态端点请求次数
200GET /v1.0/users15,070
200GET /v1.0/admin/serviceAnnouncement/healthOverviews2,676
204DELETE /v1.0/users10
204PATCH /v1.0/users7
403GET /v1.0/admin/serviceAnnouncement/healthOverviews776

请问是否有其他用户遇到相同问题?寻求解决方案。

内容的提问来源于stack exchange,提问作者floge

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 02:07:04