You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Azure Python SDK获取30天内过期的应用注册密钥

使用Azure Python SDK获取即将过期的应用注册客户端密钥列表

前置条件

  • 安装所需Python包:
    pip install azure-mgmt-graphrbac azure-identity
    
  • 完成Azure身份验证:可选择以下方式之一
    • 本地环境执行az login通过Azure CLI登录
    • 配置服务主体认证(设置对应环境变量或传入凭据参数)

代码示例

from azure.identity import DefaultAzureCredential
from azure.mgmt.graphrbac import GraphRbacManagementClient
from datetime import datetime, timedelta
import iso8601

# 替换为你的租户ID
TENANT_ID = "your-tenant-id"

# 初始化认证客户端与Graph RBAC客户端
credential = DefaultAzureCredential()
graph_client = GraphRbacManagementClient(credential, TENANT_ID)

# 计算30天后的UTC时间作为过期阈值
expiry_threshold = datetime.utcnow() + timedelta(days=30)

# 遍历所有应用注册
for application in graph_client.applications.list():
    app_id = application.app_id
    app_name = application.display_name or "无显示名称"
    
    # 检查应用是否包含客户端密钥
    if hasattr(application, 'password_credentials') and application.password_credentials:
        for pwd_cred in application.password_credentials:
            # 解析密钥过期时间
            expire_date = iso8601.parse_date(pwd_cred.end_date)
            # 判断是否在30天内过期
            if expire_date <= expiry_threshold:
                # 按指定格式输出结果
                print(f"app_id:{app_id}")
                print(f"app_display_name:{app_name}")
                print(f"password_expire:{expire_date.isoformat()}")
                print("---")  # 分隔不同密钥条目

关键说明

  • 身份验证:DefaultAzureCredential自动适配多种认证场景,避免硬编码敏感凭据
  • 筛选逻辑:以当前UTC时间+30天为阈值,对比客户端密钥的end_date字段筛选目标条目
  • 输出格式:严格匹配需求的键值对格式,每条密钥结果间用分隔线区分

内容的提问来源于stack exchange,提问作者powerlordx1

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 20:35:18