You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

更新Microsoft Graph后DelegateAuthenticationProvider缺失,如何创建Graph认证提供者?

在Microsoft Graph 5.x版本中创建AuthenticationProvider的替代方案

问题背景

在Microsoft Graph 4.54.0版本中,以下代码可正常运行:

var authProvider = new DelegateAuthenticationProvider(async (request) => {
    // Use Microsoft.Identity.Client to retrieve token
    var assertion = new UserAssertion(token.AccessToken);
    var result = await clientApplication.AcquireTokenOnBehalfOf(scopes, assertion).ExecuteAsync();

    request.Headers.Authorization =
        new System.Net.Http.Headers.AuthenticationHeaderValue("Bearer", result.AccessToken);
});

但升级到Microsoft Graph 5.0.0和Microsoft.Graph.Core 3.0.0版本后,会出现DelegateAuthenticationProvider找不到的错误,需要替换为新版本的认证实现方式。

解决方案

Microsoft Graph 5.x(配套Microsoft.Graph.Core 3.x)移除了DelegateAuthenticationProvider,推荐使用以下两种方式实现自定义认证:

方式1:继承BaseBearerTokenAuthenticationProvider实现自定义认证类

这种方式适合需要复用认证逻辑的场景:

using Microsoft.Graph;
using Microsoft.Graph.Authentication;
using Microsoft.Identity.Client;
using System.Threading;
using System.Threading.Tasks;

public class OnBehalfOfAuthProvider : BaseBearerTokenAuthenticationProvider
{
    private readonly IConfidentialClientApplication _clientApp;
    private readonly string[] _scopes;
    private readonly string _userAccessToken;

    public OnBehalfOfAuthProvider(IConfidentialClientApplication clientApp, string[] scopes, string userAccessToken)
        : base(new TokenCredentialAuthProvider())
    {
        _clientApp = clientApp;
        _scopes = scopes;
        _userAccessToken = userAccessToken;
    }

    protected override async Task<string> GetAuthorizationTokenAsync(Uri uri, Dictionary<string, object>? additionalContext = null, CancellationToken cancellationToken = default)
    {
        var userAssertion = new UserAssertion(_userAccessToken);
        var authResult = await _clientApp.AcquireTokenOnBehalfOf(_scopes, userAssertion)
                                         .ExecuteAsync(cancellationToken);
        return authResult.AccessToken;
    }
}

使用该类初始化GraphServiceClient:

// 初始化机密客户端应用(根据实际配置修改)
var confidentialClient = ConfidentialClientApplicationBuilder
    .Create("你的客户端ID")
    .WithClientSecret("你的客户端密钥")
    .WithTenantId("你的租户ID")
    .Build();

var targetScopes = new[] { "https://graph.microsoft.com/.default" };
var userToken = "用户的访问令牌"; // 传入用户的原始访问令牌

var authProvider = new OnBehalfOfAuthProvider(confidentialClient, targetScopes, userToken);
var graphClient = new GraphServiceClient(authProvider);

方式2:直接使用BearerTokenAuthenticationProvider(简化版)

如果不需要复用认证逻辑,可直接通过委托方式传入令牌获取逻辑:

using Microsoft.Graph;
using Microsoft.Graph.Authentication;
using Microsoft.Identity.Client;

// 初始化机密客户端应用
var confidentialClient = ConfidentialClientApplicationBuilder
    .Create("你的客户端ID")
    .WithClientSecret("你的客户端密钥")
    .WithTenantId("你的租户ID")
    .Build();

var targetScopes = new[] { "https://graph.microsoft.com/.default" };
var userToken = "用户的访问令牌";

var authProvider = new BearerTokenAuthenticationProvider(async (requestContext) =>
{
    var userAssertion = new UserAssertion(userToken);
    var authResult = await confidentialClient.AcquireTokenOnBehalfOf(targetScopes, userAssertion)
                                             .ExecuteAsync();
    return authResult.AccessToken;
});

var graphClient = new GraphServiceClient(authProvider);

内容的提问来源于stack exchange,提问作者Shiraz Bhaiji

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 15:57:28