You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用服务主体调用Azure DevOps PAT API更新过期时间遇权限问题

问题:自动更新Azure DevOps PAT过期时间失败

我想自动更新Azure DevOps中Personal Access Token(PAT)的过期时间。按照微软官方的API管理方案操作时,流程能正常运行,但需要用户手动登录。于是我改用PowerShell 7的Connect-AzAccount命令通过服务主体完成登录:

$azureAplicationId = "[app_id]"
$azureTenantId = "[tenant_id]"
$azurePass = ConvertTo-SecureString "[app_secret]" -AsPlainText -Force
$psCred = New-Object System.Management.Automation.PSCredential($azureAplicationId,$azurePass)

Connect-AzAccount -Credential $psCred -Tenant $azureTenantId -ServicePrincipal

接着执行以下命令成功获取到Bearer Token:

(Get-AzAccessToken -ResourceUrl "499b84ac-1321-427f-aa17-267ca6975798").Token

但在Postman中使用这个Token调用更新PAT的API时失败,返回401 Unauthorized错误,提示“The user is not authorized to access this resource”。我排查后发现,Azure AD中针对Azure DevOps的用户模拟权限仅支持委托权限,没有应用权限可选,求可行的解决思路?

内容的提问来源于stack exchange,提问作者Rodri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 12:00:57