You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何认证Microsoft Graph API并获取同组织其他用户日历事件?

配置GraphServiceClient获取同组织用户Outlook日历事件失败问题

我正尝试配置GraphServiceClient以获取同组织内其他用户的Outlook日历事件,已在Program.cs中编写相关代码并配置appsettings.json,但仍无法获取其他用户信息,怀疑是令牌生成存在问题,需要获取带有正确权限范围的有效令牌。

Program.cs代码

using Microsoft.AspNetCore.Authentication.JwtBearer;
using Microsoft.Identity.Web;
using Microsoft.OpenApi.Models;

var builder = WebApplication.CreateBuilder(args);

builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
    .AddMicrosoftIdentityWebApi(builder.Configuration.GetSection("AzureAd"))
        .EnableTokenAcquisitionToCallDownstreamApi()
            .AddMicrosoftGraph(builder.Configuration.GetSection("MicrosoftGraph"))
            .AddInMemoryTokenCaches();

builder.Services.AddControllers();

builder.Services.AddEndpointsApiExplorer();

builder.Services.AddSwaggerGen(c =>
{
    c.SwaggerDoc("v1", new OpenApiInfo
    {
        Title = "OutlookEvents",
        Version = "v1"
    });

    c.AddSecurityDefinition("oauth2", new OpenApiSecurityScheme
    {
        Type = SecuritySchemeType.OAuth2,
        Flows = new OpenApiOAuthFlows()
        {
            Implicit = new OpenApiOAuthFlow()
            {
                AuthorizationUrl = new Uri("xxx"),
                TokenUrl = new Uri("xxx"),
                Scopes = new Dictionary<string, string>
            {
               {
                  "api://xxx/xxx",
                  "xxx"
               }
             
            }
            }
    }
    });

    c.AddSecurityRequirement(new OpenApiSecurityRequirement() {
    {
        new OpenApiSecurityScheme
        {
            Reference = new OpenApiReference
            {
                    Type = ReferenceType.SecurityScheme,
                        Id = "oauth2"
            },
                Scheme = "oauth2",
                Name = "oauth2",
                In = ParameterLocation.Header
        },
        new List < string > ()
    }});

});

var app = builder.Build();

if (app.Environment.IsDevelopment())
{
    app.UseSwagger();
    app.UseSwaggerUI(c =>
    {
        c.SwaggerEndpoint("/swagger/v1/swagger.json", "OutlookEvents v1");

        c.OAuthClientId("xxx");
        c.OAuthClientSecret("xxx");

        c.OAuthUseBasicAuthenticationWithAccessCodeGrant();
    });
}

app.UseHttpsRedirection();

app.UseAuthentication();

app.UseAuthorization();

app.MapControllers();

app.Run();

appsettings.json配置

{
  "AzureAd": {
    "Instance": "https://login.microsoftonline.com/",
    "Domain": "xxx.com",
    "TenantId": "xxx",
    "ClientId": "xxx",
    "Scopes": "access_as_user",
    "CallbackPath": "/signin-oidc",
    "ClientSecret": "Client secret from app-registration. Check user secrets/azure portal.",
    "ClientCertificates": []
  },
  "Logging": {
    "LogLevel": {
      "Default": "Information",
      "Microsoft.AspNetCore": "Warning"
    }
  },
  "AllowedHosts": "*",
  "MicrosoftGraph": {
    "BaseUrl": "https://graph.microsoft.com/v1.0",
    "Scopes": [
      "user.read",
      "Calendars.Read",
      "Calendars.ReadWrite",
      "User.Read.All",
      "User.ReadWrite.All",
      "Application.Read.All",
      "Profile"
    ]
  }
}

排查与解决建议

  • 权限配置检查

    • 登录Azure AD应用注册页面,确认已添加对应权限:如果是通过用户上下文访问,需添加委托权限Calendars.Read.Shared(读取共享日历)或Calendars.ReadWrite.Shared;如果需要访问所有用户日历(无需共享),需添加应用权限Calendars.Read或Calendars.ReadWrite,且所有权限都需完成管理员同意。
    • 当前配置中的Calendars.Read仅能访问当前用户自身日历,无法获取其他用户的,需补充对应权限。
  • 令牌范围验证

    • 检查MicrosoftGraph:Scopes配置,确保包含所需的日历权限(如Calendars.Read.Shared)。
    • 使用令牌解析工具查看生成的令牌,确认scp(委托权限)或roles(应用权限)声明中包含目标权限。
  • API调用正确性

    • 调用Graph API时,需使用/users/{user-id}/calendar/events路径指定目标用户,而非默认的/me/calendar/events(仅当前用户)。
  • Swagger OAuth配置调整

    • Swagger的OAuth范围配置中,需添加Graph的相关权限(如https://graph.microsoft.com/Calendars.Read.Shared),确保获取令牌时请求了正确的范围。

内容的提问来源于stack exchange,提问作者Naligeshi Shruthi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 18:25:33