如何使Azure AD的Access Token包含多Scope?该需求是否可行?
在Azure AD Access Token中同时包含多个Scope的解决方案
问题背景
需要在同一个Access Token中包含session:role-any、email、openid、profile多个Scope以获取对应访问权限,已配置Azure AD并通过以下密码授权方式请求Token:
curl -X POST -H "Content-Type: application/x-www-form-urlencoded;charset=UTF-8" \ --data-urlencode "client_id=<client_id>" \ --data-urlencode "client_secret=<client_secret>" \ --data-urlencode "username=testuser@thoughtspot.com" \ --data-urlencode "password=*****" \ --data-urlencode "grant_type=password" \ --data-urlencode "scope=https://<application_id>/session:role-any email openid profile" \ https://login.microsoftonline.com/<tenant_id>/oauth2/v2.0/token
但解析Token后发现仅session:role-any被包含;单独请求email openid profile作为Scope时,这些Scope可正常出现在Token中。
需求可行性及解决方法
该需求完全可实现,问题源于Azure AD对不同类型Scope的处理顺序逻辑,具体调整方案如下:
1. 调整Scope参数顺序
Azure AD处理混合Scope(自定义API Scope + OpenID Connect标准Scope)时,需将OIDC标准Scope放在最前面,再追加自定义API的Scope。修改后的请求中scope参数应为:
openid email profile https://<application_id>/session:role-any
对应的完整curl命令:
curl -X POST -H "Content-Type: application/x-www-form-urlencoded;charset=UTF-8" \ --data-urlencode "client_id=<client_id>" \ --data-urlencode "client_secret=<client_secret>" \ --data-urlencode "username=testuser@thoughtspot.com" \ --data-urlencode "password=*****" \ --data-urlencode "grant_type=password" \ --data-urlencode "scope=openid email profile https://<application_id>/session:role-any" \ https://login.microsoftonline.com/<tenant_id>/oauth2/v2.0/token
2. 确认应用权限配置
- 检查Azure AD应用注册中,当前客户端应用已被授予自定义API的
session:role-any权限,且状态为“已授予” - 确认
email、profile等OIDC标准权限已启用(通常默认开启,可在应用注册的“API权限”页面验证)
3. 逻辑说明
当同时请求自定义API Scope和OIDC标准Scope时,若自定义Scope在前,Azure AD会优先生成仅针对该自定义API的Access Token,此时OIDC相关的Claims不会被注入;将OIDC标准Scope前置后,Azure AD会生成包含OIDC身份Claims和自定义API权限的复合Token,满足多Scope的需求。
参考文档:《ThoughtSpot云版:Snowflake与Azure AD OAuth连接配置》
内容的提问来源于stack exchange,提问作者Yohei Nishioka
相关产品推荐
相关产品推荐

