Azure Windows 10 VM自动启动失败:InvalidAuthenticationTokenTenant权限问题求助
Azure VM自动启停任务失败:InvalidAuthenticationTokenTenant 问题解决
错误原因
这个错误核心是身份验证令牌的租户ID与VM所属订阅的租户ID不匹配。常见触发场景:
- 订阅刚完成跨租户转移,Azure后台的租户信息未同步完成(官方提示最长1小时,实际可能需要更久)
- 自动化账户创建在旧租户下,订阅转移后未同步更新自动化账户的租户关联
- 身份验证缓存的令牌未更新,仍指向旧租户
解决步骤
1. 等待租户同步(若刚转移订阅)
如果最近操作过订阅跨租户转移,先等待1-2小时,让Azure完成全局租户信息同步,之后重试任务。
2. 核对自动化账户与订阅的租户一致性
- 登录Azure门户,打开VM所属的订阅详情页,记录租户ID
- 找到配置自动启停的自动化账户,查看其概述页的租户ID
- 若两者不一致,需在当前订阅的租户下重新创建自动化账户,再重新配置VM的自动启停规则
3. 重置自动化账户的身份验证
如果自动化账户使用服务主体身份:
- 进入自动化账户的身份页面,删除旧服务主体
- 在当前租户下创建新服务主体,为其分配
Virtual Machine Contributor权限(确保能操作VM启停) - 更新自动化任务的身份验证配置,使用新服务主体
4. 清除本地身份缓存(若使用本地触发脚本)
如果是通过本地CLI/PowerShell触发任务:
- Azure CLI:运行
az account clear清除缓存,再用正确租户登录az login --tenant <你的租户ID> - PowerShell:运行
Clear-AzContext清除上下文,再重新登录Connect-AzAccount -Tenant <你的租户ID>
错误原文引用
Unauthorized!
{ "error": { "code": "InvalidAuthenticationTokenTenant", "message": "The access token is from the wrong issuer 'https://sts.windows.net/xxxxxxxxxxxxxxxxxxxxx/'. It must match the tenant 'https://sts.windows.net/xxxxxxxxxxxxxxxxxxxxxxx/' associated with this subscription. Please use the authority (URL) 'https://login.windows.net/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx' to get the token. Note, if the subscription is transferred to another tenant there is no impact to the services, but information about new tenant could take time to propagate (up to an hour). If you just transferred your subscription and see this error message, please try back later." } }
内容的提问来源于stack exchange,提问作者agftrading
相关产品推荐
相关产品推荐

