使用API和PowerShell迁移Purview资产遇授权错误求助
Purview资产迁移PowerShell脚本未授权错误排查
我拥有一个Purview账户,账户内包含多个集合,集合下存有各类资产。已知可通过Azure Portal GUI将部分资产从一个集合迁移至另一个集合,现尝试通过API和PowerShell实现该操作,但运行以下代码时遭遇未授权错误,请求协助排查:
$tenantID = "XXXXXXXXXXXXXXXXXXXXXXXXXX" $url = "https://login.microsoftonline.com/$tenantID/oauth2/token" $params = @{ client_id = "XXXXXXXXXXXXXXXXXXXXXXX"; client_secret = "XXXXXXXXXXXXXXXXXXXXXXXXX"; grant_type = "client_credentials"; resource = ‘https://purview.azure.net’ } $bearertoken = Invoke-WebRequest $url -Method Post -Body $params -UseBasicParsing | ConvertFrom-Json $headers = @{ Authorization="Bearer " + $bearertoken.access_token Content='application/json' } $endpoint = "https://testpurview.purview.azure.com" $url1 = "$endpoint/catalog/api/collections/mycollectionname/entity/moveHere?api-version=2022-03-01-preview" $guids = @" { "entityGuids": [ "XXXXXXXXXXXXXXXXXXXXXXX" ] } "@ Invoke-WebRequest -Method POST -Uri $url1 -Body $guids -ContentType 'application/json' -Headers $headers
错误信息(已翻译):
Invoke-WebRequest: C:\Repos\Purview\PurviewAutomation\Move_assets.ps1:23:1
Line |
23 | Invoke-WebRequest -Method POST -Uri $url1 -Body $guids -ContentType ' …
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
| {"error":{"code":"Unauthorized","message":"未授权访问账户"}}
排查与解决步骤
- 修正服务主体权限
确保用于认证的服务主体(对应client_id的Azure AD应用)在Purview账户及目标/源集合上拥有足够权限:- 在Azure Portal的Purview账户「访问控制(IAM)」中,给服务主体分配数据管理员或集合管理员角色;
- 在Purview Studio的集合权限设置里,为该服务主体添加目标集合和源集合的管理员权限。
- 修复令牌请求的引号问题
代码中resource参数使用了中文单引号(‘’),需替换为英文双引号(""),否则会导致令牌受众不正确,无法通过Purview的权限校验。修正后的params部分:$params = @{ client_id = "XXXXXXXXXXXXXXXXXXXXXXX"; client_secret = "XXXXXXXXXXXXXXXXXXXXXXXXX"; grant_type = "client_credentials"; resource = "https://purview.azure.net" } - 清理冗余请求头
当前headers中的Content='application/json'属于冗余配置,已在Invoke-WebRequest中通过ContentType参数指定,可移除该条目,修正后的headers:$headers = @{ Authorization="Bearer " + $bearertoken.access_token } - 验证令牌有效性
输出$bearertoken.access_token,使用本地JWT解析工具查看:aud字段必须为https://purview.azure.net;roles或scp字段需包含与Purview资产迁移相关的权限。
- 确认API端点与版本
检查$endpoint是否为正确的Purview账户域名(格式为https://<账户名>.purview.azure.com),同时可尝试将API版本替换为最新稳定版(如2023-05-01),确保接口兼容性。
内容的提问来源于stack exchange,提问作者Subhransu Sekhar
相关产品推荐
相关产品推荐

