You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Get-MsalToken生成Azure AD TAP令牌时遇参数集解析错误求助

Azure AD TAP令牌生成问题排查

问题重现

执行以下PowerShell脚本尝试生成Azure AD TAP令牌:

$tenantId = "**********"
$clientID = "**********"
$ClientSecret = ConvertTo-SecureString "**********" -AsPlainText -Force
$Scope = "https://**************"
$redirectUri = "https://***************"
$TokenResponse = Get-MsalToken -ClientId $clientID -clientsecret $clientsecret -TenantId $tenantId -Interactive -RedirectUri $redirectUri -Scopes $Scope

第一次报错

Get-MsalToken : Parameter set cannot be resolved using the specified named parameters.
At line:1 char:18
+ $TokenResponse = get-msaltoken @connectiondetails
+                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo          : InvalidArgument: (:) [Get-MsalToken], ParameterBindingException
+ FullyQualifiedErrorId : AmbiguousParameterSet,Get-MsalToken

移除-clientsecret参数后,出现第二次报错:

Get-MsalToken : A configuration issue is preventing authentication - check the error message from the server for details. You can modify the configuration in the application registration portal. 
Original exception: AADSTS7000218: The request body must contain the following parameter: 'client_assertion' or 'client_secret'.
Trace ID: 478c441b-12e4-4968-a485-066872501300
Correlation ID: 55cf72cb-7c3c-4f4e-a26c-cfe746bb5985
Timestamp: 2023-01-15 22:04:27Z
At line:1 char:18
+ ... nResponse = Get-MsalToken -ClientId $clientID -TenantId $tenantId  -I ...
+                 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo          : AuthenticationError: (Microsoft.Ident...arameterBuilder:AcquireTokenInteractiveParameterBuilder) [Write-Error], MsalServiceException
+ FullyQualifiedErrorId : GetMsalTokenFailureAuthenticationError,Get-MsalToken

错误原因

  1. 参数集冲突:Get-MsalToken的-Interactive(交互式用户登录,对应授权码流)和-ClientSecret(客户端凭据认证,对应客户端凭据流)属于互斥的参数集,不能同时使用。
  2. 应用注册配置不匹配:移除-ClientSecret后报错AADSTS7000218,是因为应用注册被配置为机密客户端,但交互式登录的公共客户端权限未开启,导致Azure AD要求必须提供客户端凭据。

解决方案

根据使用场景选择以下两种方式:

场景1:使用交互式用户登录(授权码流)

适合需要用户手动输入账号密码的场景,无需客户端密钥:

  1. 登录Azure门户,找到目标应用注册,进入认证页面,开启允许公共客户端流(若应用为机密客户端类型)。
  2. 使用修正后的脚本:
$tenantId = "**********"
$clientID = "**********"
$Scope = "https://**************"
$redirectUri = "https://***************"
$TokenResponse = Get-MsalToken -ClientId $clientID -TenantId $tenantId -Interactive -RedirectUri $redirectUri -Scopes $Scope

场景2:使用客户端凭据流(无交互后台脚本)

适合自动化脚本、无人值守场景,无需交互式登录:

  1. 确保应用注册已配置对应的应用权限(而非委派权限),并获得管理员同意。
  2. 使用修正后的脚本(注意Scope需添加.default后缀):
$tenantId = "**********"
$clientID = "**********"
$ClientSecret = ConvertTo-SecureString "**********" -AsPlainText -Force
$Scope = "https://**************/.default"
$TokenResponse = Get-MsalToken -ClientId $clientID -ClientSecret $ClientSecret -TenantId $tenantId -Scopes $Scope

内容的提问来源于stack exchange,提问作者MDMEngineer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 04:31:19