Power Apps Portal:如何通过Liquid获取AD登录用户的用户组
Power Apps Portals 获取AD用户组并渲染PowerBI报表的实现方案
方案1:同步AD组到Dataverse,用Liquid查询(推荐)
Power Apps Portals的登录用户对应Dataverse中的Contact记录,若将本地/云端AD组同步到Dataverse的azureadsecuritygroup表,可直接通过Liquid结合FetchXML查询当前用户的所属组,进而控制报表渲染。
前提准备
- 云端AD:通过Power Platform管理员中心配置Azure AD同步,将AD组及用户-组关联同步到Dataverse;
- 本地AD:先通过Azure AD Connect同步到Azure AD,再完成上述Dataverse同步配置。
Liquid代码示例
{% assign current_user = user %} {% if current_user %} {% comment %} 查询当前用户所属的Azure AD安全组 {% endcomment %} {% fetchxml group_query %} <fetch> <entity name="azureadsecuritygroup"> <attribute name="displayname" /> <attribute name="azureadobjectid" /> <link-entity name="contact" from="contactid" to="contactid" intersect="azureadsecuritygroup_contact"> <filter> <condition attribute="contactid" operator="eq" value="{{ current_user.id }}" /> </filter> </link-entity> </entity> </fetch> {% endfetchxml %} {% if group_query.results.entities.size > 0 %} {% for group in group_query.results.entities %} {% comment %} 根据组名判断是否渲染指定PowerBI报表 {% endcomment %} {% if group.displayname == "PowerBI_销售报表查看组" %} <div class="powerbi-container"> <h4>销售业绩报表</h4> <iframe src="https://app.powerbi.com/reportEmbed?reportId=xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxx&groupId=yyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyy" width="100%" height="600" frameborder="0" allowFullScreen="true"> </iframe> </div> {% elsif group.displayname == "PowerBI_运营报表查看组" %} <div class="powerbi-container"> <h4>运营效率报表</h4> <iframe src="https://app.powerbi.com/reportEmbed?reportId=zzzzzz-zzzz-zzzz-zzzz-zzzzzzzzzz&groupId=yyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyy" width="100%" height="600" frameborder="0" allowFullScreen="true"> </iframe> </div> {% endif %} {% endfor %} {% else %} <p>暂无权限查看任何报表</p> {% endif %} {% else %} <p>请先登录系统</p> {% endif %}
方案2:调用Microsoft Graph API获取组(无需Dataverse同步)
若不想将AD组同步到Dataverse,可通过JavaScript在Portal页面调用Microsoft Graph API,直接获取当前登录用户的所属组。
实现步骤
- 在Azure AD中注册应用,授予
GroupMember.Read.All委托权限; - 在Portal页面通过内置接口获取访问令牌,调用Graph API查询组。
JavaScript代码示例
// 获取访问令牌 fetch("/_services/auth/token", { method: "POST", headers: { "Content-Type": "application/x-www-form-urlencoded" }, body: "resource=https://graph.microsoft.com&grant_type=client_credentials" }) .then(res => res.json()) .then(tokenData => { // 调用Graph API获取用户所属组 fetch("https://graph.microsoft.com/v1.0/me/memberOf", { headers: { "Authorization": `Bearer ${tokenData.access_token}` } }) .then(graphRes => graphRes.json()) .then(groupData => { groupData.value.forEach(group => { // 根据组名渲染对应报表 if (group.displayName === "PowerBI_销售报表查看组") { const reportDiv = document.createElement("div"); reportDiv.innerHTML = ` <h4>销售业绩报表</h4> <iframe src="https://app.powerbi.com/reportEmbed?reportId=xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxx&groupId=yyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyy" width="100%" height="600" frameborder="0" allowFullScreen="true"></iframe> `; document.getElementById("report-container").appendChild(reportDiv); } }); }) .catch(err => console.error("Graph API调用失败:", err)); }) .catch(err => console.error("令牌获取失败:", err));
方案3:自定义同步逻辑(实时更新组信息)
若需实时同步AD组变化,可通过以下方式实现:
- 使用Azure Logic Apps监听Azure AD组成员变更事件,触发Dataverse记录更新;
- 编写Dataverse插件,结合Azure AD Graph API定时拉取最新组信息并同步。
内容的提问来源于stack exchange,提问作者Kieran Ojakangas
相关产品推荐
相关产品推荐

