Azure AD登录后复用Token推送Azure Monitor遥测数据问题
能否复用Azure AD登录后的Access Token或ID Token推送遥测到Azure Monitor数据收集端点?
我想了解登录Azure AD后,是否可以复用获取到的Access Token或ID Token,将遥测数据推送到Azure Monitor的数据收集端点。由于以下两种验证方式均针对同一应用注册(App ID),我认为应该具备可行性,但实际测试中遇到了问题,具体测试情况如下:
【可行】通过Client Credentials模式获取https://monitor.azure.com/的Access Token并推送日志(非静默,希望实现静默登录)
$appid = myapplicationGUID $tenantId = mytenantGUID $appSecret = myappSecret $DcrImmutableId = myDCRImmutableId $DceURI = myDCEURI $Table = myTable $log_entry = myLogEntry ## Obtain a bearer token used to authenticate against the data collection endpoint $scope = [System.Web.HttpUtility]::UrlEncode("https://monitor.azure.com/.default") $body = "client_id=$appId&scope=$scope&client_secret=$appSecret&grant_type=client_credentials"; $headers = @{"Content-Type" = "application/x-www-form-urlencoded" }; $uri = "https://login.microsoftonline.com/$tenantId/oauth2/v2.0/token" $bearerToken = (Invoke-RestMethod -Uri $uri -Method "Post" -Body $body -Headers $headers).access_token $body = $log_entry | ConvertTo-Json $headers = @{"Authorization" = "Bearer $bearerToken"; "Content-Type" = "application/json" }; $uri = "$DceURI/dataCollectionRules/$DcrImmutableId/streams/Custom-$Table"+"?api-version=2021-11-01-preview"; $uploadResponse = Invoke-RestMethod -Uri $uri -Method "Post" -Body $body -Headers $headers;
【可行】使用Get-MsalToken交互式获取Microsoft Graph的Token(希望复用此Token)
$appid = myapplicationGUID $tenantId = mytenantGUID Get-MsalToken -ClientId $appid -TenantId $tenantId -Scopes ".default" -Interactive
【不可行】使用Scope https://monitor.azure.com/.default进行交互式验证
$appid = myapplicationGUID $tenantId = mytenantGUID Get-MsalToken -ClientId $appid -TenantId $tenantId -Scopes "https://monitor.azure.com/.default" -Interactive
【不可行】使用Get-MsalToken返回的AccessToken上传日志
$appid = myapplicationGUID $tenantId = mytenantGUID $DcrImmutableId = myDCRImmutableId $DceURI = myDCEURI $Table = myTable $log_entry = myLogEntry $bearerToken = (Get-MsalToken -ClientId $appid -TenantId $tenantId -Scopes ".default" -Interactive).AccessToken $body = $log_entry | ConvertTo-Json $headers = @{"Authorization" = "Bearer $bearerToken"; "Content-Type" = "application/json" }; $uri = "$DceURI/dataCollectionRules/$DcrImmutableId/streams/Custom-$Table"+"?api-version=2021-11-01-preview"; $uploadResponse = Invoke-RestMethod -Uri $uri -Method "Post" -Body $body -Headers $headers;
【不可行】使用Get-MsalToken返回的IdToken上传日志
$appid = myapplicationGUID $tenantId = mytenantGUID $DcrImmutableId = myDCRImmutableId $DceURI = myDCEURI $Table = myTable $log_entry = myLogEntry $bearerToken = (Get-MsalToken -ClientId $appid -TenantId $tenantId -Scopes ".default" -Interactive).IdToken $body = $log_entry | ConvertTo-Json $headers = @{"Authorization" = "Bearer $bearerToken"; "Content-Type" = "application/json" }; $uri = "$DceURI/dataCollectionRules/$DcrImmutableId/streams/Custom-$Table"+"?api-version=2021-11-01-preview"; $uploadResponse = Invoke-RestMethod -Uri $uri -Method "Post" -Body $body -Headers $headers;
内容的提问来源于stack exchange,提问作者Hofa
相关产品推荐
相关产品推荐

