You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD登录后复用Token推送Azure Monitor遥测数据问题

能否复用Azure AD登录后的Access Token或ID Token推送遥测到Azure Monitor数据收集端点?

我想了解登录Azure AD后,是否可以复用获取到的Access Token或ID Token,将遥测数据推送到Azure Monitor的数据收集端点。由于以下两种验证方式均针对同一应用注册(App ID),我认为应该具备可行性,但实际测试中遇到了问题,具体测试情况如下:

【可行】通过Client Credentials模式获取https://monitor.azure.com/的Access Token并推送日志(非静默,希望实现静默登录)

$appid = myapplicationGUID
$tenantId = mytenantGUID
$appSecret = myappSecret

$DcrImmutableId = myDCRImmutableId
$DceURI = myDCEURI
$Table = myTable
$log_entry = myLogEntry

## Obtain a bearer token used to authenticate against the data collection endpoint
$scope = [System.Web.HttpUtility]::UrlEncode("https://monitor.azure.com/.default")   
$body = "client_id=$appId&scope=$scope&client_secret=$appSecret&grant_type=client_credentials";
$headers = @{"Content-Type" = "application/x-www-form-urlencoded" };
$uri = "https://login.microsoftonline.com/$tenantId/oauth2/v2.0/token"
$bearerToken = (Invoke-RestMethod -Uri $uri -Method "Post" -Body $body -Headers $headers).access_token

$body = $log_entry | ConvertTo-Json
$headers = @{"Authorization" = "Bearer $bearerToken"; "Content-Type" = "application/json" };
$uri = "$DceURI/dataCollectionRules/$DcrImmutableId/streams/Custom-$Table"+"?api-version=2021-11-01-preview";
$uploadResponse = Invoke-RestMethod -Uri $uri -Method "Post" -Body $body -Headers $headers;

【可行】使用Get-MsalToken交互式获取Microsoft Graph的Token(希望复用此Token)

$appid = myapplicationGUID
$tenantId = mytenantGUID

Get-MsalToken -ClientId $appid -TenantId $tenantId -Scopes ".default" -Interactive

【不可行】使用Scope https://monitor.azure.com/.default进行交互式验证

$appid = myapplicationGUID
$tenantId = mytenantGUID

Get-MsalToken -ClientId $appid -TenantId $tenantId -Scopes "https://monitor.azure.com/.default" -Interactive

【不可行】使用Get-MsalToken返回的AccessToken上传日志

$appid = myapplicationGUID
$tenantId = mytenantGUID

$DcrImmutableId = myDCRImmutableId
$DceURI = myDCEURI
$Table = myTable
$log_entry = myLogEntry

$bearerToken = (Get-MsalToken -ClientId $appid -TenantId $tenantId -Scopes ".default" -Interactive).AccessToken

$body = $log_entry | ConvertTo-Json
$headers = @{"Authorization" = "Bearer $bearerToken"; "Content-Type" = "application/json" };
$uri = "$DceURI/dataCollectionRules/$DcrImmutableId/streams/Custom-$Table"+"?api-version=2021-11-01-preview";
$uploadResponse = Invoke-RestMethod -Uri $uri -Method "Post" -Body $body -Headers $headers;

【不可行】使用Get-MsalToken返回的IdToken上传日志

$appid = myapplicationGUID
$tenantId = mytenantGUID

$DcrImmutableId = myDCRImmutableId
$DceURI = myDCEURI
$Table = myTable
$log_entry = myLogEntry

$bearerToken = (Get-MsalToken -ClientId $appid -TenantId $tenantId -Scopes ".default" -Interactive).IdToken

$body = $log_entry | ConvertTo-Json
$headers = @{"Authorization" = "Bearer $bearerToken"; "Content-Type" = "application/json" };
$uri = "$DceURI/dataCollectionRules/$DcrImmutableId/streams/Custom-$Table"+"?api-version=2021-11-01-preview";
$uploadResponse = Invoke-RestMethod -Uri $uri -Method "Post" -Body $body -Headers $headers;

内容的提问来源于stack exchange,提问作者Hofa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 10:05:33