You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让多租户Azure Function访问其他租户的资源?

多租户Azure Function获取跨租户Graph API令牌问题及解决方案

问题背景

  • 租户A配置:
    • 创建Azure Function并启用系统托管标识,为其授予Graph API权限,确认可正常获取访问令牌并访问Graph API
    • 添加Azure AD身份验证,创建App Registration,配置所需Graph API权限并启用多租户访问选项
  • 租户B操作:
    • 通过专属URL启动租户A应用的管理员同意流程,确认需同意租户A App Registration中指定的权限,且租户B中已生成该应用的企业应用条目

遇到的问题

无论尝试何种配置,始终无法获取租户B上下文的Graph API访问令牌,返回的始终是租户A托管标识的令牌,只能访问租户A的信息。

尝试的代码如下:

var credential = new DefaultAzureCredential(new DefaultAzureCredentialOptions { AdditionallyAllowedTenants = { "*" }, TenantId = "<Tenant B ID>" });
var token = credential.GetToken(
    new Azure.Core.TokenRequestContext(
        new[] { "https://graph.microsoft.com/.default" }, null, null, "<Tenant B ID"));
var accessToken = token.Token;

试过的组合及结果:

  • 按文档指定租户B ID后,仍返回租户A的令牌
  • 移除DefaultAzureCredentialOptions仅在GetToken中指定租户ID,会触发需添加AdditionallyAllowedTenants选项的提示,添加后依旧无法获取目标租户的令牌

需求:实现多租户Azure Function在请求来源租户的上下文内,使用对应租户的身份访问资源,目前已能从认证Claims中获取租户ID,但无法获取对应租户的令牌。

更新与解决方案

需使用租户A App Registration的客户端ID、密钥/证书进行认证,而非系统托管标识,以此请求租户B的令牌。

证书认证代码示例

var appToken = new ClientCertificateCredential(tenantID, appID, appCert, new ClientCertificateCredentialOptions { AdditionallyAllowedTenants = { "*" } });
var graphServiceClient = new GraphServiceClient(appToken);

变量说明

  • tenantID:租户B的ID
  • appID:租户A的App Registration客户端ID
  • appCert:租户A的App Registration证书

注意:需将AdditionallyAllowedTenants配置为"*",允许获取任意租户的令牌,再用该凭据构建连接租户B的GraphServiceClient。


内容的提问来源于stack exchange,提问作者Appleoddity

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 07:31:19