使用服务主体调用Azure DevOps PAT API更新过期时间遇权限问题
问题:自动更新Azure DevOps PAT过期时间失败
我想自动更新Azure DevOps中Personal Access Token(PAT)的过期时间。按照微软官方的API管理方案操作时,流程能正常运行,但需要用户手动登录。于是我改用PowerShell 7的Connect-AzAccount命令通过服务主体完成登录:
$azureAplicationId = "[app_id]" $azureTenantId = "[tenant_id]" $azurePass = ConvertTo-SecureString "[app_secret]" -AsPlainText -Force $psCred = New-Object System.Management.Automation.PSCredential($azureAplicationId,$azurePass) Connect-AzAccount -Credential $psCred -Tenant $azureTenantId -ServicePrincipal
接着执行以下命令成功获取到Bearer Token:
(Get-AzAccessToken -ResourceUrl "499b84ac-1321-427f-aa17-267ca6975798").Token
但在Postman中使用这个Token调用更新PAT的API时失败,返回401 Unauthorized错误,提示“The user is not authorized to access this resource”。我排查后发现,Azure AD中针对Azure DevOps的用户模拟权限仅支持委托权限,没有应用权限可选,求可行的解决思路?
内容的提问来源于stack exchange,提问作者Rodri
相关产品推荐
相关产品推荐

