You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AccessToken的Azure CSP客户订阅创建PowerShell脚本失败

Azure CSP客户订阅创建问题:AccessToken认证无法获取计费账户

我用以下脚本创建Azure CSP客户订阅,使用DeviceAuthentication时可正常运行,但使用AccessToken时失败(无法获取billingaccount),且无任何错误提示。由于要在Azure Automation Runbook中运行,无法使用基于GUI的认证,必须通过AccessToken实现该功能。

param (
    [Parameter(Mandatory=$true)]
    [String]
    $custID,
    [Parameter(Mandatory=$true)]
    [String]
    $subscriptionName
)

If (Get-Module -ListAvailable -Name PartnerCenter) {
    Write-Host "Module exists"
} 
else {
    Install-Module -Name PartnerCenter -AllowClobber -Scope CurrentUser -Force
}
$access_token = "<AccessToken>"
try {
    #Connect-PartnerCenter -UseDeviceAuthentication
    Connect-PartnerCenter -AccessToken $access_token -TenantID "<TenantID>"
    $BillingAccount = Get-PartnerAzureBillingAccount | Where-Object {$_.AgreementType -eq 'MicrosoftCustomerAgreement'}
    Get-PartnerCustomer -CustomerId $CustID
    $BillingAccount
    $Subscription = New-PartnerAzureSubscription -BillingAccountName $BillingAccount.Name -CustomerId $custID -DisplayName $subscriptionName
    "New Subscription created sucessfully. Details below."
    $Subscription
}
catch {
    "Error creating New Subscription"
}

排查与解决建议

  • 检查AccessToken权限范围:确保AccessToken包含Partner Center API的必要权限https://api.partnercenter.microsoft.com/user_impersonation,且是针对合作伙伴租户的权限,而非客户租户。
  • 验证AccessToken有效性:解码JWT令牌,确认aud(受众)为https://api.partnercenter.microsoft.com,tid匹配合作伙伴租户ID,且exp(过期时间)未到期。
  • 增强错误捕获:原脚本的catch块过于简略,替换为以下代码获取详细错误信息:
    catch {
        Write-Error "创建订阅失败: $_"
        Write-Error "错误详情: $($_.Exception.Message)"
        Write-Error "堆栈跟踪: $($_.ScriptStackTrace)"
    }
    
  • 确认计费账户返回结果:在Connect-PartnerCenter后添加Get-PartnerAzureBillingAccount | Format-List,查看是否有MicrosoftCustomerAgreement类型的账户,避免过滤后得到空值。
  • 改用服务主体认证:自动化场景下推荐使用服务主体替代直接传AccessToken:
    1. 在合作伙伴租户创建服务主体,分配全局管理员或合作伙伴中心计费管理员角色
    2. 在Azure Automation中创建凭据资产存储服务主体的应用ID与密钥
    3. 修改连接代码:
      $cred = Get-AutomationPSCredential -Name "你的凭据名称"
      Connect-PartnerCenter -ApplicationId $cred.UserName -Credential $cred -TenantId "<合作伙伴租户ID>"
      

内容的提问来源于stack exchange,提问作者IsmailKhan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 03:35:25