使用Graph API访问Microsoft Tasks时遭遇accessDenied问题
Microsoft Graph API访问Tasks报accessDenied问题排查
问题描述
我正尝试通过Python应用调用Graph API访问Microsoft Tasks,使用的代码如下:
client = msal.ConfidentialClientApplication(client_id, authority=authority, client_credential=client_secret) # First, try to lookup an access token in cache token_result = client.acquire_token_silent(scope, account=None) # If the token is available in cache, save it to a variable if token_result: access_token = 'Bearer ' + token_result['access_token'] print('Access token was loaded from cache') # If the token is not available in cache, acquire a new one from Azure AD and save it to a variable if not token_result: token_result = client.acquire_token_for_client(scopes=scope) access_token = 'Bearer ' + token_result['access_token'] # print('New access token was acquired from Azure AD') # print(access_token) url = 'https://graph.microsoft.com/v1.0/users/ae444444-4444-448f-be95-f58390836cca/todo/lists' headers = { 'Authorization': access_token } graph_result = requests.get(url=url, headers=headers) print(graph_result.json())
但始终收到accessDenied响应,尽管我已配置Task.Read.All应用权限,请问这是什么原因?
排查方向及解决办法
- 权限未完成管理员同意:
Task.Read.All作为应用权限,必须由租户管理员执行授予管理员同意操作才会生效。仅在Azure AD中添加权限但未完成同意,应用无法实际获取该权限的访问权限。 - Scope参数配置错误:使用客户端凭证流(
acquire_token_for_client)时,scope必须设置为https://graph.microsoft.com/.default。客户端凭证流依赖预先配置的应用权限,.default表示请求所有已配置的应用权限集合,若scope值不正确,令牌将不包含所需权限。 - 用户ID或请求路径验证:确认URL中的用户ID(
ae444444-4444-448f-be95-f58390836cca)准确无误,且该用户存在于你的租户中,同时应用具备访问该用户任务列表的权限。 - 令牌权限校验:把拿到的access_token解码,查看
roles字段里有没有Task.Read.All。如果没有,说明令牌没获取到对应权限,回去检查权限配置和scope设置。
内容的提问来源于stack exchange,提问作者pepsilon
相关产品推荐
相关产品推荐

