You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Power Apps Portal:如何通过Liquid获取AD登录用户的用户组

Power Apps Portals 获取AD用户组并渲染PowerBI报表的实现方案

方案1:同步AD组到Dataverse,用Liquid查询(推荐)

Power Apps Portals的登录用户对应Dataverse中的Contact记录,若将本地/云端AD组同步到Dataverse的azureadsecuritygroup表,可直接通过Liquid结合FetchXML查询当前用户的所属组,进而控制报表渲染。

前提准备

  • 云端AD:通过Power Platform管理员中心配置Azure AD同步,将AD组及用户-组关联同步到Dataverse;
  • 本地AD:先通过Azure AD Connect同步到Azure AD,再完成上述Dataverse同步配置。

Liquid代码示例

{% assign current_user = user %}
{% if current_user %}
  {% comment %} 查询当前用户所属的Azure AD安全组 {% endcomment %}
  {% fetchxml group_query %}
  <fetch>
    <entity name="azureadsecuritygroup">
      <attribute name="displayname" />
      <attribute name="azureadobjectid" />
      <link-entity name="contact" from="contactid" to="contactid" intersect="azureadsecuritygroup_contact">
        <filter>
          <condition attribute="contactid" operator="eq" value="{{ current_user.id }}" />
        </filter>
      </link-entity>
    </entity>
  </fetch>
  {% endfetchxml %}

  {% if group_query.results.entities.size > 0 %}
    {% for group in group_query.results.entities %}
      {% comment %} 根据组名判断是否渲染指定PowerBI报表 {% endcomment %}
      {% if group.displayname == "PowerBI_销售报表查看组" %}
        <div class="powerbi-container">
          <h4>销售业绩报表</h4>
          <iframe 
            src="https://app.powerbi.com/reportEmbed?reportId=xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxx&groupId=yyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyy"
            width="100%" 
            height="600" 
            frameborder="0" 
            allowFullScreen="true">
          </iframe>
        </div>
      {% elsif group.displayname == "PowerBI_运营报表查看组" %}
        <div class="powerbi-container">
          <h4>运营效率报表</h4>
          <iframe 
            src="https://app.powerbi.com/reportEmbed?reportId=zzzzzz-zzzz-zzzz-zzzz-zzzzzzzzzz&groupId=yyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyy"
            width="100%" 
            height="600" 
            frameborder="0" 
            allowFullScreen="true">
          </iframe>
        </div>
      {% endif %}
    {% endfor %}
  {% else %}
    <p>暂无权限查看任何报表</p>
  {% endif %}
{% else %}
  <p>请先登录系统</p>
{% endif %}

方案2:调用Microsoft Graph API获取组(无需Dataverse同步)

若不想将AD组同步到Dataverse,可通过JavaScript在Portal页面调用Microsoft Graph API,直接获取当前登录用户的所属组。

实现步骤

  1. 在Azure AD中注册应用,授予GroupMember.Read.All委托权限;
  2. 在Portal页面通过内置接口获取访问令牌,调用Graph API查询组。

JavaScript代码示例

// 获取访问令牌
fetch("/_services/auth/token", {
  method: "POST",
  headers: { "Content-Type": "application/x-www-form-urlencoded" },
  body: "resource=https://graph.microsoft.com&grant_type=client_credentials"
})
.then(res => res.json())
.then(tokenData => {
  // 调用Graph API获取用户所属组
  fetch("https://graph.microsoft.com/v1.0/me/memberOf", {
    headers: { "Authorization": `Bearer ${tokenData.access_token}` }
  })
  .then(graphRes => graphRes.json())
  .then(groupData => {
    groupData.value.forEach(group => {
      // 根据组名渲染对应报表
      if (group.displayName === "PowerBI_销售报表查看组") {
        const reportDiv = document.createElement("div");
        reportDiv.innerHTML = `
          <h4>销售业绩报表</h4>
          <iframe src="https://app.powerbi.com/reportEmbed?reportId=xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxx&groupId=yyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyy" 
                  width="100%" height="600" frameborder="0" allowFullScreen="true"></iframe>
        `;
        document.getElementById("report-container").appendChild(reportDiv);
      }
    });
  })
  .catch(err => console.error("Graph API调用失败:", err));
})
.catch(err => console.error("令牌获取失败:", err));

方案3:自定义同步逻辑(实时更新组信息)

若需实时同步AD组变化,可通过以下方式实现:

  • 使用Azure Logic Apps监听Azure AD组成员变更事件,触发Dataverse记录更新;
  • 编写Dataverse插件,结合Azure AD Graph API定时拉取最新组信息并同步。

内容的提问来源于stack exchange,提问作者Kieran Ojakangas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 06:41:15