能否使用现有Access Token请求Microsoft认证的额外权限范围?
Great question—this is a common point of confusion with Azure AD's OAuth flows, so let's break it down clearly.
Straight Answer
No, you cannot use your existing Dynamics access token to request additional scopes (like User.Read for Microsoft Graph) or a new token for a different resource. This isn't a random limitation—it's a deliberate security design choice in Azure AD.
Why This Won't Work
Let's get into the details:
- Access tokens are locked to a specific resource: Your current token is issued exclusively for the Dynamics 365 admin center (its
audclaim points tohttps://admin.services.crm.dynamics.com) with only theuser_impersonationscope. Azure AD signs tokens to verify their intended audience, so it will reject any attempt to repurpose this token for Microsoft Graph or add new permissions to it. - Access tokens aren't meant for refreshing: Unlike refresh tokens, access tokens are short-lived (usually 60-90 minutes) and built only for accessing resources, not for obtaining new tokens. They don't carry the necessary credentials to authorize a scope expansion—refresh tokens are the only valid mechanism for that.
- Security first: Allowing access tokens to gain new scopes would create a massive privilege escalation risk. If a token were compromised, an attacker could potentially add high-permission scopes without needing user consent or valid refresh credentials.
What You Can Do Instead
Since you want to avoid refresh tokens (though they're the recommended path), here are your options:
Use your refresh token to get a Microsoft Graph token (the seamless way)
Even though you mentioned avoiding it, this is the best user experience. You can call theoauth2/v2.0/tokenendpoint with your refresh token, specifying theUser.Readscope for Graph. Since refresh tokens are tied to your user's session, this won't require any interaction from the user.
Example request body (for confidential clients):grant_type=refresh_token &client_id=your-client-id &client_secret=your-client-secret &refresh_token=your-refresh-token &scope=https://graph.microsoft.com/User.Read- Note: You can use the same refresh token to get tokens for both Dynamics and Graph—you just need separate calls for each resource.
Re-run the authorization code flow for Microsoft Graph
If you really don't want to use a refresh token, you'll need to send the user through the authorization process again, this time requesting theUser.Readscope. If the user has already consented to this scope for your app, they might not even see a prompt (depending on your tenant's settings). You'll get a new authorization code, which you can exchange for a Graph access token.
Quick Correction to Your Original Thought
You mentioned that you "can only request a single scope/audience at a time"—actually, the Azure AD v2 endpoint lets you request multiple scopes in one authorization request, as long as they're for resources that accept the same consent framework. For example, if you'd wanted to request both Dynamics user_impersonation and Graph User.Read upfront, you could use a scope string like:
https://admin.services.crm.dynamics.com/user_impersonation https://graph.microsoft.com/User.Read
That said, you'll still get separate access tokens for each resource—there's no way to get one token that works for both Dynamics and Graph, since each token is tied to a single audience.
Final Takeaway
While avoiding refresh tokens might feel like a simpler choice, they're purpose-built for scenarios like this: getting new access tokens without forcing users to re-login. They're securely stored, long-lived (based on your app configuration), and the most efficient way to get the Graph token you need.
内容的提问来源于stack exchange,提问作者Simon

