Azure企业应用创建与配置自动化的问题求助
Azure Enterprise Application 自动化配置解决方案
1. identifierUris 报错问题解决
报错Values of identifierUris property must use a verified domain of the organization or its subdomain的核心原因是Azure AD对标识符URI的强制验证规则,针对你的场景可按以下步骤排查解决:
- 确认域名验证状态:你手动创建时能正常使用的URL,其域名必然已在Azure AD租户中完成验证(包括默认的
<tenant>.onmicrosoft.com域名)。检查脚本中指定的identifierUris,确保域名在Azure门户→Azure AD→自定义域名列表中显示为「已验证」。 - 使用免验证格式:若不想配置自定义域名,可采用Azure AD允许的免验证格式,比如
api://<client-id>(<client-id>为应用注册的客户端ID),或者https://<tenant-name>.onmicrosoft.com/<app-name>。 - MS Graph 规范配置:用MS Graph API创建应用注册时,显式指定合法的
identifierUris,避免使用未验证的外部域名。示例代码:$appParams = @{ displayName = "Your Enterprise App" identifierUris = @("https://your-verified-domain.com/your-app") tags = @("WindowsAzureActiveDirectoryIntegratedApp") } New-MgApplication -BodyParameter $appParams
2. SAML Attributes & Claims 字段编辑方案
上传SAML元数据与证书
- PowerShell 实现:通过Microsoft Graph PowerShell模块完成跨平台配置,无需依赖Windows:
- 将XML格式证书转换为PEM格式(提取
X509Certificate节点内容,添加-----BEGIN CERTIFICATE-----和-----END CERTIFICATE-----首尾标识)。 - 添加令牌签名证书并关联到SAML配置:
# 添加令牌签名证书 $certParams = @{ displayName = "SAML Signing Cert" endDateTime = (Get-Date).AddYears(1) content = "PEM格式证书内容" format = "pem" } $cert = New-MgServicePrincipalTokenSigningCertificate -ServicePrincipalId $spId -BodyParameter $certParams # 配置SAML单点登录设置 $samlParams = @{ singleSignOnConfiguration = @{ "@odata.type" = "#microsoft.graph.samlSingleSignOnSettings" relayState = "https://your-app-relay-state-url" samlResponseSigning = "response-only" signingCertificateId = $cert.Id } } Update-MgServicePrincipal -ServicePrincipalId $spId -BodyParameter $samlParams
- 将XML格式证书转换为PEM格式(提取
- Terraform 修复生效问题:需搭配
azuread_service_principal_saml_single_sign_on资源,将上传的证书关联到SAML配置,避免单纯上传证书后未生效:resource "azuread_service_principal_certificate" "saml_cert" { service_principal_id = azuread_service_principal.sp.id type = "AsymmetricX509Cert" encoding = "PEM" value = file("path/to/your/cert.pem") } resource "azuread_service_principal_saml_single_sign_on" "saml_sso" { service_principal_id = azuread_service_principal.sp.id relay_state = "https://your-app-url" signing_certificate_id = azuread_service_principal_certificate.saml_cert.id # 其他SAML配置项 }
编辑Attributes & Claims
通过声明映射策略实现自定义属性配置,步骤如下:
- 创建自定义声明映射策略:
$policyDef = @' { "ClaimsMappingPolicy": { "Version": 1, "IncludeBasicClaimSet": true, "ClaimsSchema": [ { "Source": "user", "ID": "userprincipalname", "SamlClaimType": "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier" }, { "Source": "user", "ID": "department", "SamlClaimType": "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/department" } ] } } '@ $policy = New-MgPolicyClaimMappingPolicy -Definition @($policyDef) -DisplayName "Custom SAML Claims Policy" - 将策略关联到目标服务主体:
New-MgServicePrincipalClaimMappingPolicyByRef ` -ServicePrincipalId $spId ` -BodyParameter @{ "@odata.id" = "https://graph.microsoft.com/v1.0/policies/claimsMappingPolicies/$($policy.Id)" }
内容的提问来源于stack exchange,提问作者Alex Bishka
相关产品推荐
相关产品推荐

