Azure Communication Services Azure IAM认证配置及报错排查咨询
Azure Communication Services IAM认证配置问题
问题背景
我使用Azure Communication Services实现了短信和邮件发送功能,通过端点+访问密钥或连接字符串可正常运行,但这并非最佳实践,希望改用Azure IAM进行认证。
IAM角色分配疑问
在以下操作流程中,第4步应分配什么角色,后续该如何操作?
- 在Azure门户中导航至用于发送短信的Azure Communication Services资源
- 点击左侧菜单中的“Access control (IAM)”选项卡
- 点击“Add role assignment”按钮
- 下一步应如何操作?
代码切换后的异常情况
我切换到使用DefaultAzureCredential的代码重载:
var options = new DefaultAzureCredentialOptions { ExcludeInteractiveBrowserCredential = false, ExcludeManagedIdentityCredential = true, ExcludeSharedTokenCacheCredential = false, InteractiveBrowserTenantId = tenantId, InteractiveBrowserCredentialClientId = clientId, ManagedIdentityClientId = clientId, SharedTokenCacheTenantId = tenantId, TenantId = tenantId, VisualStudioTenantId = tenantId, VisualStudioCodeTenantId = tenantId }; var tokenCredentials = new DefaultAzureCredential(options); var emailClient = new EmailClient(new Uri(uri), tokenCredentials);
尝试发送短信或邮件时出现权限错误:The request is not authorized with Azure Active Directory (AAD) access token.
执行命令 az login --scope https://communication.azure.com//.default 时也失败,报错:AADSTS70011: The provided request must include a 'scope' input parameter. The provided value for the input parameter 'scope' is not valid. The scope https://communication.azure.com//.default is not valid.
注意:仅Azure Communication Services出现此问题,Key Vault、AppConfiguration等其他Azure服务的IAM认证可正常工作。
使用访问密钥可正常运行的代码
public sealed class AzureEmailNotificationService { private readonly EmailConfiguration _emailConfiguration; private readonly EmailClient _emailClient; public AzureEmailNotificationService(IOptions<EmailConfiguration> options) { ArgumentNullException.ThrowIfNull(options.Value); _emailConfiguration = options.Value; _emailClient = new EmailClient(new Uri(_emailConfiguration.Endpoint), new AzureKeyCredential(_emailConfiguration.AccessKey)); } public async Task SendAsync(string subject, string message, string recipient, CancellationToken cancellationToken = default) { var emailContent = new EmailContent(subject) { PlainText = message }; var emailAddresses = new List<EmailAddress> { new(recipient) }; var emailRecipients = new EmailRecipients(emailAddresses); await _emailClient.SendAsync(new EmailMessage(_emailConfiguration.From, emailContent, emailRecipients), cancellationToken); } } public sealed class AzureSmsNotificationService { private readonly SmsConfiguration _smsConfiguration; private readonly SmsClient _smsClient; public AzureSmsNotificationService(IOptions<SmsConfiguration> options) { ArgumentNullException.ThrowIfNull(options.Value); _smsConfiguration = options.Value; _smsClient = new SmsClient(new Uri(_smsConfiguration.Endpoint), new AzureKeyCredential(_smsConfiguration.AccessKey)); } public async Task SendAsync(string message, string recipient, CancellationToken cancellationToken = default) { await _smsClient.SendAsync(_smsConfiguration.From, recipient, message, cancellationToken: cancellationToken); } }
内容的提问来源于stack exchange,提问作者nop
相关产品推荐
相关产品推荐

