You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure企业应用创建与配置自动化的问题求助

Azure Enterprise Application 自动化配置解决方案

1. identifierUris 报错问题解决

报错Values of identifierUris property must use a verified domain of the organization or its subdomain的核心原因是Azure AD对标识符URI的强制验证规则,针对你的场景可按以下步骤排查解决:

  • 确认域名验证状态:你手动创建时能正常使用的URL,其域名必然已在Azure AD租户中完成验证(包括默认的<tenant>.onmicrosoft.com域名)。检查脚本中指定的identifierUris,确保域名在Azure门户→Azure AD→自定义域名列表中显示为「已验证」。
  • 使用免验证格式:若不想配置自定义域名,可采用Azure AD允许的免验证格式,比如api://<client-id>(<client-id>为应用注册的客户端ID),或者https://<tenant-name>.onmicrosoft.com/<app-name>。
  • MS Graph 规范配置:用MS Graph API创建应用注册时,显式指定合法的identifierUris,避免使用未验证的外部域名。示例代码:
    $appParams = @{
      displayName = "Your Enterprise App"
      identifierUris = @("https://your-verified-domain.com/your-app")
      tags = @("WindowsAzureActiveDirectoryIntegratedApp")
    }
    New-MgApplication -BodyParameter $appParams
    

2. SAML Attributes & Claims 字段编辑方案

上传SAML元数据与证书

  • PowerShell 实现:通过Microsoft Graph PowerShell模块完成跨平台配置,无需依赖Windows:
    1. 将XML格式证书转换为PEM格式(提取X509Certificate节点内容,添加-----BEGIN CERTIFICATE-----和-----END CERTIFICATE-----首尾标识)。
    2. 添加令牌签名证书并关联到SAML配置:
      # 添加令牌签名证书
      $certParams = @{
        displayName = "SAML Signing Cert"
        endDateTime = (Get-Date).AddYears(1)
        content = "PEM格式证书内容"
        format = "pem"
      }
      $cert = New-MgServicePrincipalTokenSigningCertificate -ServicePrincipalId $spId -BodyParameter $certParams
      
      # 配置SAML单点登录设置
      $samlParams = @{
        singleSignOnConfiguration = @{
          "@odata.type" = "#microsoft.graph.samlSingleSignOnSettings"
          relayState = "https://your-app-relay-state-url"
          samlResponseSigning = "response-only"
          signingCertificateId = $cert.Id
        }
      }
      Update-MgServicePrincipal -ServicePrincipalId $spId -BodyParameter $samlParams
      
  • Terraform 修复生效问题:需搭配azuread_service_principal_saml_single_sign_on资源,将上传的证书关联到SAML配置,避免单纯上传证书后未生效:
    resource "azuread_service_principal_certificate" "saml_cert" {
      service_principal_id = azuread_service_principal.sp.id
      type                 = "AsymmetricX509Cert"
      encoding             = "PEM"
      value                = file("path/to/your/cert.pem")
    }
    
    resource "azuread_service_principal_saml_single_sign_on" "saml_sso" {
      service_principal_id = azuread_service_principal.sp.id
      relay_state          = "https://your-app-url"
      signing_certificate_id = azuread_service_principal_certificate.saml_cert.id
      # 其他SAML配置项
    }
    

编辑Attributes & Claims

通过声明映射策略实现自定义属性配置,步骤如下:

  1. 创建自定义声明映射策略:
    $policyDef = @'
    {
      "ClaimsMappingPolicy": {
        "Version": 1,
        "IncludeBasicClaimSet": true,
        "ClaimsSchema": [
          {
            "Source": "user",
            "ID": "userprincipalname",
            "SamlClaimType": "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier"
          },
          {
            "Source": "user",
            "ID": "department",
            "SamlClaimType": "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/department"
          }
        ]
      }
    }
    '@
    
    $policy = New-MgPolicyClaimMappingPolicy -Definition @($policyDef) -DisplayName "Custom SAML Claims Policy"
    
  2. 将策略关联到目标服务主体:
    New-MgServicePrincipalClaimMappingPolicyByRef `
      -ServicePrincipalId $spId `
      -BodyParameter @{ "@odata.id" = "https://graph.microsoft.com/v1.0/policies/claimsMappingPolicies/$($policy.Id)" }
    

内容的提问来源于stack exchange,提问作者Alex Bishka

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 10:05:29