You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Graph API访问Microsoft Tasks时遭遇accessDenied问题

Microsoft Graph API访问Tasks报accessDenied问题排查

问题描述

我正尝试通过Python应用调用Graph API访问Microsoft Tasks,使用的代码如下:

client = msal.ConfidentialClientApplication(client_id, authority=authority, client_credential=client_secret)

# First, try to lookup an access token in cache
token_result = client.acquire_token_silent(scope, account=None)

# If the token is available in cache, save it to a variable
if token_result:
  access_token = 'Bearer ' + token_result['access_token']
  print('Access token was loaded from cache')

# If the token is not available in cache, acquire a new one from Azure AD and save it to a variable
if not token_result:
  token_result = client.acquire_token_for_client(scopes=scope)
  access_token = 'Bearer ' + token_result['access_token']
#   print('New access token was acquired from Azure AD')

# print(access_token)


url = 'https://graph.microsoft.com/v1.0/users/ae444444-4444-448f-be95-f58390836cca/todo/lists'
headers = {
    'Authorization': access_token
}

graph_result = requests.get(url=url, headers=headers)

print(graph_result.json())

但始终收到accessDenied响应,尽管我已配置Task.Read.All应用权限,请问这是什么原因?

排查方向及解决办法

  • 权限未完成管理员同意:Task.Read.All作为应用权限,必须由租户管理员执行授予管理员同意操作才会生效。仅在Azure AD中添加权限但未完成同意,应用无法实际获取该权限的访问权限。
  • Scope参数配置错误:使用客户端凭证流(acquire_token_for_client)时,scope必须设置为https://graph.microsoft.com/.default。客户端凭证流依赖预先配置的应用权限,.default表示请求所有已配置的应用权限集合,若scope值不正确,令牌将不包含所需权限。
  • 用户ID或请求路径验证:确认URL中的用户ID(ae444444-4444-448f-be95-f58390836cca)准确无误,且该用户存在于你的租户中,同时应用具备访问该用户任务列表的权限。
  • 令牌权限校验:把拿到的access_token解码,查看roles字段里有没有Task.Read.All。如果没有,说明令牌没获取到对应权限,回去检查权限配置和scope设置。

内容的提问来源于stack exchange,提问作者pepsilon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 20:41:08