You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

从Azure Data Factory向Service Bus发消息时遇HTTP 401错误求助

Azure Data Factory向Service Bus发送消息报401未授权问题排查

问题背景

我尝试复现实验,实现从Azure Data Factory(ADF)向Azure Service Bus发送消息。已按照指引为ADF的托管标识分配了「Azure Service Bus Data Sender」角色,但执行管道时触发401未授权错误。

错误信息

Error code   : 2108
Failure type : User configuration issue
Details      : Invoking Web Activity failed with HttpStatusCode - 
               '401 : Unauthorized', message - ''
Source       : Pipeline Service Bus REST API

当前管道配置

{
    "name": "Service Bus REST API",
    "properties": {
        "activities": [
            {
                "name": "Service Bus REST API",
                "description": "Teste",
                "type": "WebActivity",
                "dependsOn": [],
                "policy": {
                    "timeout": "7.00:00:00",
                    "retry": 0,
                    "retryIntervalInSeconds": 30,
                    "secureOutput": false,
                    "secureInput": false
                },
                "userProperties": [],
                "typeProperties": {
                    "url": "https://sb-namespace-dv.servicebus.windows.net/sbt-azure-adf-ntt-data-test/messages",
                    "method": "POST",
                    "headers": {
                        "CustomHeader-Version": "\"1.0\"",
                        "Content-Type": "application/json",
                        "BrokerProperties": {
                            "value": "@concat('{\"CorrelationId\": \"',pipeline().RunId,'\"}')",
                            "type": "Expression"
                        }
                    },
                    "body": {
                        "value": "{\"message\":{\"value\":\"@variables('OutputDetails')\",\"type\":\"Expression\"}}",
                        "type": "Expression"
                    },
                    "httpRequestTimeout": "00:10:00",
                    "authentication": {
                        "type": "MSI",
                        "resource": "https://servicebus.azure.net"
                    }
                }
            }
        ],
        "folder": {
            "name": "999_Others/9910_DevTest/TesteServiceBusADF"
        },
        "annotations": []
    }
}

期望结果

{
    "message": "Snapshot Avaliable"
}

问题排查与修复建议

  • 角色分配范围与延迟:确认「Azure Service Bus Data Sender」角色分配到Service Bus命名空间层级,而非仅队列级别。Azure RBAC角色分配可能存在5-10分钟的延迟,分配完成后请等待一段时间再重试。
  • MSI认证Resource参数修正:将authentication中的resource值改为https://servicebus.azure.net/(添加末尾斜杠),部分场景下缺少斜杠会导致令牌颁发不符合要求。
  • Header格式修正:CustomHeader-Version的当前值包含多余双引号,应修改为"1.0",避免Header格式无效。
  • Body表达式修正:当前Body的表达式写法错误,会将变量名直接作为字符串输出,无法解析变量值。建议修改为以下两种方式之一:
    方式一:
    "body": {
        "value": "@json(concat('{\"message\": \"', variables('OutputDetails'), '\"}'))",
        "type": "Expression"
    }
    
    方式二:
    "body": {
        "message": {
            "value": "@variables('OutputDetails')",
            "type": "Expression"
        }
    }
    
  • 队列权限验证:通过Azure门户检查目标队列sbt-azure-adf-ntt-data-test的「访问控制(IAM)」页面,确认ADF托管标识的「Azure Service Bus Data Sender」角色分配记录存在且生效。

内容的提问来源于stack exchange,提问作者Sergio Coutinho

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 10:45:41