You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Azure PowerShell Function连接B2C租户的Microsoft Graph(Connect-MgGraph)

Azure PowerShell Function 非交互式管理 Azure B2C 用户的可行方案

方案1:应用注册 + 证书(解决你之前的私钥问题)

你之前踩的坑是只上传了公钥(.cer),没把带私钥的PFX证书部署到Function的证书存储里。正确操作步骤:

  • 生成包含私钥的PFX证书(本地用New-SelfSignedCertificate生成,或用CA签发证书)
  • 把PFX证书上传到Azure Function的SSL证书(Function App左侧菜单「设置」→「SSL证书」,选「私有证书(.pfx)」上传)
  • 在B2C租户的应用注册中,上传该证书的公钥(.cer),并授予应用权限的Microsoft Graph权限(比如User.ReadWrite.All,必须完成管理员同意)
  • PowerShell Function中用证书指纹连接Graph:
$certThumbprint = "你的证书指纹"
# Azure Function的PowerShell环境中,证书存放在Cert:\CurrentUser\My
$cert = Get-ChildItem Cert:\CurrentUser\My | Where-Object {$_.Thumbprint -eq $certThumbprint}

Connect-MgGraph -ClientId "你的应用注册ClientID" -TenantId "你的B2C租户ID/域名" -Certificate $cert

方案2:客户端凭据(Client Secret)快速实现

嫌证书折腾?直接用应用注册的Client Secret做非交互式认证,步骤更简单:

  • 在B2C租户的应用注册里创建客户端密码(Client Secret)
  • 授予应用应用权限的Graph权限(比如User.ReadWrite.All,完成管理员同意)
  • Function中用Client Secret连接:
$clientId = "你的应用注册ClientID"
$clientSecret = ConvertTo-SecureString "你的Client Secret" -AsPlainText -Force
$tenantId = "你的B2C租户ID/域名"
$credential = [System.Management.Automation.PSCredential]::new($clientId, $clientSecret)

Connect-MgGraph -ClientCredential $credential -TenantId $tenantId

注意:别硬编码Client Secret,存到Azure Key Vault,用Function的托管身份去读取。

方案3:绕开Connect-MgGraph,直接用Get-AzAccessToken调用API

你之前遇到的Connect-MgGraph参数冲突问题,完全可以绕开它,直接拿令牌调用Graph REST API:

  • 确保Function的托管身份(系统/用户分配)在B2C租户的应用注册中被授予应用权限(托管身份是主AD身份,需在B2C租户中给它分配权限)
  • 获取B2C租户的Graph令牌,然后直接调用API:
$tenantId = "你的B2C租户ID"
$token = Get-AzAccessToken -TenantId $tenantId -ResourceUrl "https://graph.microsoft.com"

$headers = @{Authorization = "Bearer $($token.Token)"}
# 示例:获取B2C用户列表
Invoke-RestMethod -Uri "https://graph.microsoft.com/v1.0/users" -Headers $headers -Method Get
# 示例:创建B2C用户
$newUserBody = @{
    accountEnabled = $true
    displayName = "Test B2C User"
    mailNickname = "testb2cuser"
    userPrincipalName = "testb2cuser@yourb2ctenant.onmicrosoft.com"
    passwordProfile = @{
        forceChangePasswordNextSignIn = $true
        password = "StrongPass123!"
    }
} | ConvertTo-Json
Invoke-RestMethod -Uri "https://graph.microsoft.com/v1.0/users" -Headers $headers -Method Post -Body $newUserBody -ContentType "application/json"

核心注意点

  • 必须用应用权限,非交互式场景没有用户上下文,委派权限没用
  • 所有Graph权限都需要完成管理员同意,否则会报权限不足
  • 一定要指定B2C租户的ID/域名,别用主AD的租户ID
  • 坚持用Microsoft Graph PowerShell模块,AzureAD模块确实已废弃

内容的提问来源于stack exchange,提问作者iQueue

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 06:55:22