如何认证Microsoft Graph API并获取同组织其他用户日历事件?
配置GraphServiceClient获取同组织用户Outlook日历事件失败问题
我正尝试配置GraphServiceClient以获取同组织内其他用户的Outlook日历事件,已在Program.cs中编写相关代码并配置appsettings.json,但仍无法获取其他用户信息,怀疑是令牌生成存在问题,需要获取带有正确权限范围的有效令牌。
Program.cs代码
using Microsoft.AspNetCore.Authentication.JwtBearer; using Microsoft.Identity.Web; using Microsoft.OpenApi.Models; var builder = WebApplication.CreateBuilder(args); builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme) .AddMicrosoftIdentityWebApi(builder.Configuration.GetSection("AzureAd")) .EnableTokenAcquisitionToCallDownstreamApi() .AddMicrosoftGraph(builder.Configuration.GetSection("MicrosoftGraph")) .AddInMemoryTokenCaches(); builder.Services.AddControllers(); builder.Services.AddEndpointsApiExplorer(); builder.Services.AddSwaggerGen(c => { c.SwaggerDoc("v1", new OpenApiInfo { Title = "OutlookEvents", Version = "v1" }); c.AddSecurityDefinition("oauth2", new OpenApiSecurityScheme { Type = SecuritySchemeType.OAuth2, Flows = new OpenApiOAuthFlows() { Implicit = new OpenApiOAuthFlow() { AuthorizationUrl = new Uri("xxx"), TokenUrl = new Uri("xxx"), Scopes = new Dictionary<string, string> { { "api://xxx/xxx", "xxx" } } } } }); c.AddSecurityRequirement(new OpenApiSecurityRequirement() { { new OpenApiSecurityScheme { Reference = new OpenApiReference { Type = ReferenceType.SecurityScheme, Id = "oauth2" }, Scheme = "oauth2", Name = "oauth2", In = ParameterLocation.Header }, new List < string > () }}); }); var app = builder.Build(); if (app.Environment.IsDevelopment()) { app.UseSwagger(); app.UseSwaggerUI(c => { c.SwaggerEndpoint("/swagger/v1/swagger.json", "OutlookEvents v1"); c.OAuthClientId("xxx"); c.OAuthClientSecret("xxx"); c.OAuthUseBasicAuthenticationWithAccessCodeGrant(); }); } app.UseHttpsRedirection(); app.UseAuthentication(); app.UseAuthorization(); app.MapControllers(); app.Run();
appsettings.json配置
{ "AzureAd": { "Instance": "https://login.microsoftonline.com/", "Domain": "xxx.com", "TenantId": "xxx", "ClientId": "xxx", "Scopes": "access_as_user", "CallbackPath": "/signin-oidc", "ClientSecret": "Client secret from app-registration. Check user secrets/azure portal.", "ClientCertificates": [] }, "Logging": { "LogLevel": { "Default": "Information", "Microsoft.AspNetCore": "Warning" } }, "AllowedHosts": "*", "MicrosoftGraph": { "BaseUrl": "https://graph.microsoft.com/v1.0", "Scopes": [ "user.read", "Calendars.Read", "Calendars.ReadWrite", "User.Read.All", "User.ReadWrite.All", "Application.Read.All", "Profile" ] } }
排查与解决建议
权限配置检查
- 登录Azure AD应用注册页面,确认已添加对应权限:如果是通过用户上下文访问,需添加委托权限
Calendars.Read.Shared(读取共享日历)或Calendars.ReadWrite.Shared;如果需要访问所有用户日历(无需共享),需添加应用权限Calendars.Read或Calendars.ReadWrite,且所有权限都需完成管理员同意。 - 当前配置中的
Calendars.Read仅能访问当前用户自身日历,无法获取其他用户的,需补充对应权限。
- 登录Azure AD应用注册页面,确认已添加对应权限:如果是通过用户上下文访问,需添加委托权限
令牌范围验证
- 检查
MicrosoftGraph:Scopes配置,确保包含所需的日历权限(如Calendars.Read.Shared)。 - 使用令牌解析工具查看生成的令牌,确认
scp(委托权限)或roles(应用权限)声明中包含目标权限。
- 检查
API调用正确性
- 调用Graph API时,需使用
/users/{user-id}/calendar/events路径指定目标用户,而非默认的/me/calendar/events(仅当前用户)。
- 调用Graph API时,需使用
Swagger OAuth配置调整
- Swagger的OAuth范围配置中,需添加Graph的相关权限(如
https://graph.microsoft.com/Calendars.Read.Shared),确保获取令牌时请求了正确的范围。
- Swagger的OAuth范围配置中,需添加Graph的相关权限(如
内容的提问来源于stack exchange,提问作者Naligeshi Shruthi
相关产品推荐
相关产品推荐

