You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用C#与GraphClient创建Azure访问评审失败求助

解决Azure访问评审创建时的PartnerData错误

问题背景

尝试通过Microsoft Graph创建Azure访问评审时,官方文档的C#示例代码已过时(原PostAsync方法不再可用),修改为AddAsync后运行报错:

Message: PartnerData | Partner Record with Id 00000000-0000-0000-0000-000000000000 not found in repository

修改后的代码如下:

Console.WriteLine($"Creating AR for Group {groupid}");
var ar = new AccessReviewScheduleDefinition();
ar.DisplayName = "One-time self-review for members of Building security";
ar.DescriptionForAdmins = "One-time self-review for members of Building security";
ar.DescriptionForReviewers = "One-time self-review for members of Building security";
ar.Scope = new AccessReviewScope
{
  AdditionalData = new Dictionary<string, object>
  {           
    {
      ///transitiveMembers - Self Review
      "query" , $"/groups/{groupid}/owners"
    },
    {
      "queryType" , "MicrosoftGraph"
    },
  },
};
ar.InstanceEnumerationScope = new AccessReviewScope
{
  AdditionalData = new Dictionary<string, object>
  {
    {
      "query" , $"/groups/{groupid}"
    },
    {
      "queryType" , "MicrosoftGraph"
    },
  },
};
ar.Settings = new AccessReviewScheduleSettings
{
  MailNotificationsEnabled = true,
  ReminderNotificationsEnabled = true,
  JustificationRequiredOnApproval = true,
  DefaultDecisionEnabled = true,
  DefaultDecision = "Deny",
  InstanceDurationInDays = 5,
  AutoApplyDecisionsEnabled = true,
  RecommendationsEnabled = true,
  Recurrence = new PatternedRecurrence
  {
      Pattern = new RecurrencePattern
      {
        Type = RecurrencePatternType.Weekly,
        Interval = 1,
      },
      Range = new RecurrenceRange
      {
        Type = RecurrenceRangeType.NoEnd,
        StartDate = new Date(2023,03,15),
      },
  },
};
try
{
var result = await graphClient.IdentityGovernance.AccessReviews.Definitions.Request().AddAsync(ar);
 Console.WriteLine(result);
}
catch(Exception ex)
{
Console.WriteLine(ex.Message);
}

错误原因分析

这个错误通常由以下问题导致:

  • 评审配置矛盾:DisplayName声明为一次性评审,但Settings中配置了无限期每周重复的Recurrence,导致Graph服务无法识别评审类型。
  • 缺少评审者配置:自我评审场景下未明确指定评审者为self,Graph无法确定评审主体。
  • Scope配置不匹配:当前Scope指向群组所有者,但InstanceEnumerationScope是群组,两者的评审逻辑不匹配。

修正后的代码

以下是适配一次性自我评审场景的修复代码:

Console.WriteLine($"Creating AR for Group {groupid}");
var ar = new AccessReviewScheduleDefinition
{
    DisplayName = "One-time self-review for members of Building security",
    DescriptionForAdmins = "One-time self-review for members of Building security",
    DescriptionForReviewers = "Please review your access to the Building security group",
    // 配置要评审的主体:群组所有成员
    Scope = new AccessReviewScope
    {
        AdditionalData = new Dictionary<string, object>
        {
            {"query", $"/groups/{groupid}/members"},
            {"queryType", "MicrosoftGraph"}
        }
    },
    // 配置评审的目标资源:目标群组
    InstanceEnumerationScope = new AccessReviewScope
    {
        AdditionalData = new Dictionary<string, object>
        {
            {"query", $"/groups/{groupid}"},
            {"queryType", "MicrosoftGraph"}
        }
    },
    Settings = new AccessReviewScheduleSettings
    {
        MailNotificationsEnabled = true,
        ReminderNotificationsEnabled = true,
        JustificationRequiredOnApproval = true,
        DefaultDecisionEnabled = true,
        DefaultDecision = "Deny",
        InstanceDurationInDays = 5,
        AutoApplyDecisionsEnabled = true,
        RecommendationsEnabled = true,
        // 一次性评审不需要重复周期,移除Recurrence配置
    },
    // 关键配置:指定自我评审的评审者为当前用户
    Reviewers = new List<AccessReviewReviewerScope>
    {
        new AccessReviewReviewerScope
        {
            Query = "./self",
            QueryType = "MicrosoftGraph"
        }
    }
};

try
{
    var result = await graphClient.IdentityGovernance.AccessReviews.Definitions.Request().AddAsync(ar);
    Console.WriteLine($"Access review created successfully. ID: {result.Id}");
}
catch (Exception ex)
{
    Console.WriteLine($"Error creating access review: {ex.Message}");
    // 捕获GraphServiceException获取更详细的错误详情
    if (ex is GraphServiceException graphEx)
    {
        Console.WriteLine($"Graph error details: {graphEx.ResponseBody}");
    }
}

关键修改说明

  1. 移除Recurrence配置:一次性评审无需重复周期,若需周期性评审,保留Recurrence并更新DisplayName为对应描述。
  2. 添加Reviewers配置:通过./self指定自我评审,明确Graph的评审主体。
  3. 修正Scope查询:将/groups/{groupid}/owners改为/groups/{groupid}/members,匹配成员访问权限评审场景。
  4. 增强错误捕获:添加GraphServiceException捕获,获取更详细的错误响应信息。

额外检查项

  • 确保应用已获得IdentityGovernanceAccessReview.ReadWrite.All应用权限(需管理员同意)。
  • 确认groupid为有效的Azure AD群组ID,且应用有权限访问该群组。

内容的提问来源于stack exchange,提问作者David Steadman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 12:53:16