You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure DevOps创建服务连接时授权失败问题求助

Azure DevOps服务连接授权失败解决方案

已在Azure门户创建Azure AD应用,在Azure DevOps项目设置中新建服务连接时,验证出现错误:

Failed to query service connection API "https://managemant.azure.com/sub/xxx?api-version=2016-06-01. status code: {"error": {"code": "Authorization failed", "message": "the client with object id [xxx] does not have authorization to perform action 'Microsoft.Resources/subscriptions/read' over scope '/sub/xxx' or scope is invalid. If access was recently granted, please refresh your credentials."}}

解决步骤

  • 为Azure AD应用分配订阅权限

    1. 登录Azure门户,进入目标订阅,打开「访问控制(IAM)」
    2. 点击「添加」→「添加角色分配」
    3. 选择至少包含Microsoft.Resources/subscriptions/read权限的角色(如「读者(Reader)」或「参与者(Contributor)」)
    4. 在「成员」页签选择「用户、组或服务主体」,搜索目标Azure AD应用的名称或对象ID,完成角色分配
  • 修正服务连接配置错误

    1. 检查Azure DevOps服务连接页面的订阅ID、租户ID、客户端ID、客户端密钥,确保与Azure AD应用的信息完全一致
    2. 注意错误信息中的URL拼写错误:managemant.azure.com应为management.azure.com,需确认服务连接配置中是否存在该笔误
  • 同步权限并重新验证

    1. 权限分配完成后等待5-10分钟,让Azure权限同步生效
    2. 在Azure DevOps服务连接页面点击「重新验证」,输入正确凭据后重试

内容的提问来源于stack exchange,提问作者robert

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 11:05:17