Azure应用注册添加多resourceAccesses时遇重复值错误排查
解决Azure AD应用添加多个Scope时报错"Request contains a property with duplicate values"
问题原因
你的核心问题是生成的JSON文件中,同一个ResourceAppId(此处为Microsoft Graph的AppId)被重复定义了多次——每个权限都单独对应一个RequiredResourceAccess对象。Azure AD要求:针对同一个资源(如MS Graph)的所有权限必须合并到同一个RequiredResourceAccess条目下,不允许重复出现相同的resourceAppId,这就是导致报错的直接原因。
修正方案:调整PowerShell代码生成正确的JSON
修改PowerShell逻辑,将所有同资源的权限合并到单个RequiredResourceAccess对象的ResourceAccess数组中:
# 获取Microsoft Graph服务主体(确保已正确获取该对象) $msGraphPrincipal = Get-AzureADServicePrincipal -Filter "displayName eq 'Microsoft Graph'" # 创建单个RequiredResourceAccess对象,对应MS Graph资源 $Aad = New-Object -TypeName "Microsoft.Open.AzureAD.Model.RequiredResourceAccess" $Aad.ResourceAppId = $msGraphPrincipal.AppId # 批量创建所有需要的ResourceAccess对象 $delPermissions = @( New-Object -TypeName "Microsoft.Open.AzureAD.Model.ResourceAccess" -ArgumentList "37f7f235-527c-4136-accd-4a02d197296e", "Scope", New-Object -TypeName "Microsoft.Open.AzureAD.Model.ResourceAccess" -ArgumentList "64a6cdd6-aab1-4aaf-94b8-3cc8405e90d0", "Scope", New-Object -TypeName "Microsoft.Open.AzureAD.Model.ResourceAccess" -ArgumentList "7427e0e9-2fba-42fe-b0c0-848c9e6a8182", "Scope", New-Object -TypeName "Microsoft.Open.AzureAD.Model.ResourceAccess" -ArgumentList "14dad69e-099b-42c9-810b-d002981feec1", "Scope", New-Object -TypeName "Microsoft.Open.AzureAD.Model.ResourceAccess" -ArgumentList "e1fe6dd8-ba31-4d61-89e7-88639da4683d", "Scope" ) # 将所有权限添加到同一个ResourceAccess数组 $Aad.ResourceAccess = $delPermissions # 转换为JSON并保存(-Depth参数确保嵌套结构完整,排除冗余属性) $Aad | ConvertTo-Json -Depth 3 | Out-File "requiredResourceAccesses.json"
生成的正确JSON格式示例:
[ { "resourceAccess": [ { "id": "37f7f235-527c-4136-accd-4a02d197296e", "type": "Scope" }, { "id": "64a6cdd6-aab1-4aaf-94b8-3cc8405e90d0", "type": "Scope" }, { "id": "7427e0e9-2fba-42fe-b0c0-848c9e6a8182", "type": "Scope" }, { "id": "14dad69e-099b-42c9-810b-d002981feec1", "type": "Scope" }, { "id": "e1fe6dd8-ba31-4d61-89e7-88639da4683d", "type": "Scope" } ], "resourceAppId": "<Microsoft Graph的实际AppId>" } ]
此时再执行原Azure CLI命令即可成功部署。
其他添加多Scope的方法
1. 直接使用Azure CLI参数(无需JSON文件)
如果权限数量不多,可直接在命令中传入JSON字符串:
az ad app create --display-name MytestApp --native-app false --required-resource-accesses '[{ "resourceAppId": "<Microsoft Graph AppId>", "resourceAccess": [ {"id": "37f7f235-527c-4136-accd-4a02d197296e", "type": "Scope"}, {"id": "64a6cdd6-aab1-4aaf-94b8-3cc8405e90d0", "type": "Scope"}, {"id": "7427e0e9-2fba-42fe-b0c0-848c9e6a8182", "type": "Scope"}, {"id": "14dad69e-099b-42c9-810b-d002981feec1", "type": "Scope"}, {"id": "e1fe6dd8-ba31-4d61-89e7-88639da4683d", "type": "Scope"} ] }]' --reply-urls <你的回复URL>
2. 使用Microsoft Graph API(v1.0)
直接调用Graph API创建应用并指定权限:
POST https://graph.microsoft.com/v1.0/applications Content-Type: application/json { "displayName": "MytestApp", "publicClient": {"redirectUris": ["<你的回复URL>"]}, "requiredResourceAccess": [ { "resourceAppId": "<Microsoft Graph AppId>", "resourceAccess": [ {"id": "37f7f235-527c-4136-accd-4a02d197296e", "type": "Scope"}, {"id": "64a6cdd6-aab1-4aaf-94b8-3cc8405e90d0", "type": "Scope"}, {"id": "7427e0e9-2fba-42fe-b0c0-848c9e6a8182", "type": "Scope"}, {"id": "14dad69e-099b-42c9-810b-d002981feec1", "type": "Scope"}, {"id": "e1fe6dd8-ba31-4d61-89e7-88639da4683d", "type": "Scope"} ] } ] }
内容的提问来源于stack exchange,提问作者Amal Ps
相关产品推荐
相关产品推荐

