使用C#与GraphClient创建Azure访问评审失败求助
解决Azure访问评审创建时的PartnerData错误
问题背景
尝试通过Microsoft Graph创建Azure访问评审时,官方文档的C#示例代码已过时(原PostAsync方法不再可用),修改为AddAsync后运行报错:
Message: PartnerData | Partner Record with Id 00000000-0000-0000-0000-000000000000 not found in repository
修改后的代码如下:
Console.WriteLine($"Creating AR for Group {groupid}"); var ar = new AccessReviewScheduleDefinition(); ar.DisplayName = "One-time self-review for members of Building security"; ar.DescriptionForAdmins = "One-time self-review for members of Building security"; ar.DescriptionForReviewers = "One-time self-review for members of Building security"; ar.Scope = new AccessReviewScope { AdditionalData = new Dictionary<string, object> { { ///transitiveMembers - Self Review "query" , $"/groups/{groupid}/owners" }, { "queryType" , "MicrosoftGraph" }, }, }; ar.InstanceEnumerationScope = new AccessReviewScope { AdditionalData = new Dictionary<string, object> { { "query" , $"/groups/{groupid}" }, { "queryType" , "MicrosoftGraph" }, }, }; ar.Settings = new AccessReviewScheduleSettings { MailNotificationsEnabled = true, ReminderNotificationsEnabled = true, JustificationRequiredOnApproval = true, DefaultDecisionEnabled = true, DefaultDecision = "Deny", InstanceDurationInDays = 5, AutoApplyDecisionsEnabled = true, RecommendationsEnabled = true, Recurrence = new PatternedRecurrence { Pattern = new RecurrencePattern { Type = RecurrencePatternType.Weekly, Interval = 1, }, Range = new RecurrenceRange { Type = RecurrenceRangeType.NoEnd, StartDate = new Date(2023,03,15), }, }, }; try { var result = await graphClient.IdentityGovernance.AccessReviews.Definitions.Request().AddAsync(ar); Console.WriteLine(result); } catch(Exception ex) { Console.WriteLine(ex.Message); }
错误原因分析
这个错误通常由以下问题导致:
- 评审配置矛盾:DisplayName声明为一次性评审,但Settings中配置了无限期每周重复的Recurrence,导致Graph服务无法识别评审类型。
- 缺少评审者配置:自我评审场景下未明确指定评审者为
self,Graph无法确定评审主体。 - Scope配置不匹配:当前Scope指向群组所有者,但InstanceEnumerationScope是群组,两者的评审逻辑不匹配。
修正后的代码
以下是适配一次性自我评审场景的修复代码:
Console.WriteLine($"Creating AR for Group {groupid}"); var ar = new AccessReviewScheduleDefinition { DisplayName = "One-time self-review for members of Building security", DescriptionForAdmins = "One-time self-review for members of Building security", DescriptionForReviewers = "Please review your access to the Building security group", // 配置要评审的主体:群组所有成员 Scope = new AccessReviewScope { AdditionalData = new Dictionary<string, object> { {"query", $"/groups/{groupid}/members"}, {"queryType", "MicrosoftGraph"} } }, // 配置评审的目标资源:目标群组 InstanceEnumerationScope = new AccessReviewScope { AdditionalData = new Dictionary<string, object> { {"query", $"/groups/{groupid}"}, {"queryType", "MicrosoftGraph"} } }, Settings = new AccessReviewScheduleSettings { MailNotificationsEnabled = true, ReminderNotificationsEnabled = true, JustificationRequiredOnApproval = true, DefaultDecisionEnabled = true, DefaultDecision = "Deny", InstanceDurationInDays = 5, AutoApplyDecisionsEnabled = true, RecommendationsEnabled = true, // 一次性评审不需要重复周期,移除Recurrence配置 }, // 关键配置:指定自我评审的评审者为当前用户 Reviewers = new List<AccessReviewReviewerScope> { new AccessReviewReviewerScope { Query = "./self", QueryType = "MicrosoftGraph" } } }; try { var result = await graphClient.IdentityGovernance.AccessReviews.Definitions.Request().AddAsync(ar); Console.WriteLine($"Access review created successfully. ID: {result.Id}"); } catch (Exception ex) { Console.WriteLine($"Error creating access review: {ex.Message}"); // 捕获GraphServiceException获取更详细的错误详情 if (ex is GraphServiceException graphEx) { Console.WriteLine($"Graph error details: {graphEx.ResponseBody}"); } }
关键修改说明
- 移除Recurrence配置:一次性评审无需重复周期,若需周期性评审,保留Recurrence并更新DisplayName为对应描述。
- 添加Reviewers配置:通过
./self指定自我评审,明确Graph的评审主体。 - 修正Scope查询:将
/groups/{groupid}/owners改为/groups/{groupid}/members,匹配成员访问权限评审场景。 - 增强错误捕获:添加GraphServiceException捕获,获取更详细的错误响应信息。
额外检查项
- 确保应用已获得
IdentityGovernanceAccessReview.ReadWrite.All应用权限(需管理员同意)。 - 确认
groupid为有效的Azure AD群组ID,且应用有权限访问该群组。
内容的提问来源于stack exchange,提问作者David Steadman
相关产品推荐
相关产品推荐

