You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Communication Services Azure IAM认证配置及报错排查咨询

Azure Communication Services IAM认证配置问题

问题背景

我使用Azure Communication Services实现了短信和邮件发送功能,通过端点+访问密钥或连接字符串可正常运行,但这并非最佳实践,希望改用Azure IAM进行认证。

IAM角色分配疑问

在以下操作流程中,第4步应分配什么角色,后续该如何操作?

  1. 在Azure门户中导航至用于发送短信的Azure Communication Services资源
  2. 点击左侧菜单中的“Access control (IAM)”选项卡
  3. 点击“Add role assignment”按钮
  4. 下一步应如何操作?

代码切换后的异常情况

我切换到使用DefaultAzureCredential的代码重载:

var options = new DefaultAzureCredentialOptions
{
    ExcludeInteractiveBrowserCredential = false,
    ExcludeManagedIdentityCredential = true,
    ExcludeSharedTokenCacheCredential = false,
    InteractiveBrowserTenantId = tenantId,
    InteractiveBrowserCredentialClientId = clientId,
    ManagedIdentityClientId = clientId,
    SharedTokenCacheTenantId = tenantId,
    TenantId = tenantId,
    VisualStudioTenantId = tenantId,
    VisualStudioCodeTenantId = tenantId
};
var tokenCredentials = new DefaultAzureCredential(options);

var emailClient = new EmailClient(new Uri(uri), tokenCredentials);

尝试发送短信或邮件时出现权限错误:The request is not authorized with Azure Active Directory (AAD) access token.

执行命令 az login --scope https://communication.azure.com//.default 时也失败,报错:AADSTS70011: The provided request must include a 'scope' input parameter. The provided value for the input parameter 'scope' is not valid. The scope https://communication.azure.com//.default is not valid.

注意:仅Azure Communication Services出现此问题,Key Vault、AppConfiguration等其他Azure服务的IAM认证可正常工作。

使用访问密钥可正常运行的代码

public sealed class AzureEmailNotificationService
{
    private readonly EmailConfiguration _emailConfiguration;
    private readonly EmailClient _emailClient;

    public AzureEmailNotificationService(IOptions<EmailConfiguration> options)
    {
        ArgumentNullException.ThrowIfNull(options.Value);
        
        _emailConfiguration = options.Value;
        _emailClient = new EmailClient(new Uri(_emailConfiguration.Endpoint), new AzureKeyCredential(_emailConfiguration.AccessKey));
    }

    public async Task SendAsync(string subject, string message, string recipient, CancellationToken cancellationToken = default)
    {
        var emailContent = new EmailContent(subject) { PlainText = message };
        var emailAddresses = new List<EmailAddress> { new(recipient) };
        var emailRecipients = new EmailRecipients(emailAddresses);
        
        await _emailClient.SendAsync(new EmailMessage(_emailConfiguration.From, emailContent, emailRecipients), cancellationToken);
    }
}

public sealed class AzureSmsNotificationService
{
    private readonly SmsConfiguration _smsConfiguration;
    private readonly SmsClient _smsClient;

    public AzureSmsNotificationService(IOptions<SmsConfiguration> options)
    {
        ArgumentNullException.ThrowIfNull(options.Value);
        
        _smsConfiguration = options.Value;
        _smsClient = new SmsClient(new Uri(_smsConfiguration.Endpoint), new AzureKeyCredential(_smsConfiguration.AccessKey));   
    }

    public async Task SendAsync(string message, string recipient, CancellationToken cancellationToken = default)
    {
        await _smsClient.SendAsync(_smsConfiguration.From, recipient, message, cancellationToken: cancellationToken);
    }
}

内容的提问来源于stack exchange,提问作者nop

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 17:42:25