Microsoft Graph API邀请Azure来宾用户时公司及使用位置字段填充问题
问题描述
我在完善Python代码时遇到技术问题:该代码从Jira工单获取邮箱、姓名、公司、国家等字段,调用Microsoft Graph API邀请外部合作伙伴加入Azure环境。我已在invitation对象中传入companyName和usageLocation字段,但Azure外部来宾用户的对应字段未被成功填充,找不到相关文档指引,想问下是否支持该操作,或者有没有解决方法?
代码片段
# Microsoft Graph app = ConfidentialClientApplication( client_id=client_id, client_credential=client_secret, authority=f'https://login.microsoftonline.com/{tenant_id}' ) # 获取B2B邀请API的访问令牌 scopes = ['https://graph.microsoft.com/.default'] result = app.acquire_token_silent(scopes=scopes, account=None) if not result: result = app.acquire_token_for_client(scopes=scopes) access_token = result['access_token'] # 创建邀请对象 invitation = { 'invitedUserDisplayName': first_name + " " + last_name, 'invitedUserEmailAddress': email, 'givenName': first_name, 'surname': last_name, 'companyName': company, 'usageLocation': country, 'inviteRedirectUrl': 'https://tenant.sharepoint.com/', 'sendInvitationMessage': True, 'invitedUserMessageInfo': { 'customizedMessageBody': 'Hi {email_adress}, you can find more information here: https://www.eliostruyf.com' } } try: response = requests.post( 'https://graph.microsoft.com/beta/invitations', headers={ 'Authorization': 'Bearer ' + access_token, 'Content-Type': 'application/json' }, json=invitation ) response.raise_for_status() # 检查响应是否包含HTTP错误状态码(4xx或5xx) print(response.json()) except requests.exceptions.HTTPError as errh: print("HTTP Error:", errh) except requests.exceptions.ConnectionError as errc: print("Error Connecting:", errc) except requests.exceptions.Timeout as errt: print("Timeout Error:", errt) except requests.exceptions.RequestException as err: print("Something went wrong:", err)
解决方法
核心原因
Graph API的invitation对象本身不支持直接设置companyName和usageLocation,这两个属性属于Azure AD用户实体,而非邀请请求对象,因此直接在邀请参数里传入不会生效。
具体步骤
- 确认权限:确保你的应用已获得
User.ReadWrite.All或Directory.ReadWrite.All权限(需Azure AD管理员同意)。 - 创建邀请并获取用户ID:成功发送邀请请求后,从响应中提取来宾用户的ID(
response.json()['invitedUser']['id'])。 - 调用用户更新接口:使用提取到的用户ID,发送PATCH请求更新用户的
companyName和usageLocation字段。
修改后的代码示例
try: # 第一步:创建邀请 response = requests.post( 'https://graph.microsoft.com/beta/invitations', headers={ 'Authorization': 'Bearer ' + access_token, 'Content-Type': 'application/json' }, json=invitation ) response.raise_for_status() invite_response = response.json() print("邀请创建成功:", invite_response) # 第二步:提取来宾用户ID invited_user_id = invite_response['invitedUser']['id'] # 第三步:更新用户属性 user_update_data = { 'companyName': company, 'usageLocation': country.strip().upper() # 确保是两位ISO国家代码,比如"CN"、"US" } update_response = requests.patch( f'https://graph.microsoft.com/beta/users/{invited_user_id}', headers={ 'Authorization': 'Bearer ' + access_token, 'Content-Type': 'application/json' }, json=user_update_data ) update_response.raise_for_status() print("用户属性更新成功:", update_response.json()) except requests.exceptions.HTTPError as errh: print("HTTP Error:", errh) except requests.exceptions.ConnectionError as errc: print("Error Connecting:", errc) except requests.exceptions.Timeout as errt: print("Timeout Error:", errt) except requests.exceptions.RequestException as err: print("Something went wrong:", err)
注意事项
usageLocation必须是ISO 3166-1 alpha-2标准的两位大写国家代码,比如"CN"(中国)、"US"(美国),传入全称或非标准代码会导致设置失败。- 如果邀请创建后用户尚未接受邀请,仍然可以更新其属性,属性会在用户接受邀请后同步显示。
内容的提问来源于stack exchange,提问作者MichaelDae
相关产品推荐
相关产品推荐

