You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

企业应用无Client Secret时如何刷新Microsoft Graph API令牌?

维持企业应用Access Token有效性的替代方案

由于企业应用不允许创建Client Secret,无法通过常规的refresh_token+client_secret方式刷新Access Token,可通过以下几种方法维持Token有效性:

1. 使用客户端证书替代Client Secret

将证书上传至企业应用的证书凭据中,刷新Token时通过证书签名生成断言来验证应用身份,无需Client Secret:

  • 手动构造请求示例:
    先用证书生成JWT断言(可通过OpenSSL或PowerShell的New-JwtToken模块生成),再发起POST请求:
    POST https://login.microsoftonline.com/common/oauth2/v2.0/token
    Content-Type: application/x-www-form-urlencoded
    
    grant_type=refresh_token&
    refresh_token=[REFRESH TOKEN]&
    client_id=[APPLICATION ID]&
    client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer&
    client_assertion=[JWT断言内容]&
    scope=[SCOPE]&
    redirect_uri=[REDIRECT URI]
    
  • PowerShell实现:
    借助Az.Accounts模块结合证书完成身份验证,后续操作会自动维护Token刷新:
    # 从本地证书存储导入目标证书
    $cert = Get-ChildItem Cert:\CurrentUser\My\证书指纹
    # 通过证书验证连接到Azure
    Connect-AzAccount -ApplicationId [应用ID] -Certificate $cert -Tenant [租户ID]
    

2. 使用托管标识(Managed Identity)

如果应用部署在Azure服务(如VM、App Service、Azure Function等)上,可启用托管标识,由Azure自动管理Token的生成与刷新,完全无需手动维护:

  • 系统分配托管标识:
    在Azure门户为目标服务启用系统分配标识后,通过以下方式获取Token:
    $token = Invoke-RestMethod -Uri "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=[目标资源URI]" -Headers @{Metadata="true"}
    $accessToken = $token.access_token
    
  • 用户分配托管标识:
    创建用户分配标识并关联到服务后,请求时指定标识ID即可:
    $token = Invoke-RestMethod -Uri "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=[目标资源URI]&client_id=[用户分配标识ID]" -Headers @{Metadata="true"}
    

3. 使用交互式登录并持久化会话

对于PowerShell场景,通过交互式登录获取会话后,将上下文保存到本地,后续恢复会话时自动维持Token有效性:

# 发起交互式登录
Connect-AzAccount -Interactive
# 保存会话上下文到本地文件
Save-AzContext -Path "C:\temp\az_context.json"
# 后续恢复会话(无需重复登录)
Import-AzContext -Path "C:\temp\az_context.json"
# 执行操作时会自动触发Token刷新
Get-AzResourceGroup

4. 使用设备授权流(Device Code Flow)

适合无UI的服务器/终端场景,用户通过手机等设备完成授权,获取的Refresh Token可用于刷新Access Token,无需Client Secret:

# 发起设备授权请求
$deviceCodeReq = Invoke-RestMethod -Uri "https://login.microsoftonline.com/common/oauth2/v2.0/devicecode" -Method Post -Body @{
    client_id = "[应用ID]"
    scope = "[所需权限范围]"
}
# 提示用户完成授权
Write-Host $deviceCodeReq.message
# 轮询获取Token
do {
    Start-Sleep -Seconds $deviceCodeReq.interval
    $tokenRes = Invoke-RestMethod -Uri "https://login.microsoftonline.com/common/oauth2/v2.0/token" -Method Post -Body @{
        grant_type = "urn:ietf:params:oauth:grant-type:device_code"
        client_id = "[应用ID]"
        device_code = $deviceCodeReq.device_code
    } -ErrorAction SilentlyContinue
} while (-not $tokenRes)
# 提取Refresh Token用于后续刷新
$refreshToken = $tokenRes.refresh_token

内容的提问来源于stack exchange,提问作者Manoj Dwivedi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 23:20:29