如何通过Microsoft Graph Java SDK创建Azure AD来宾用户?
创建Azure AD来宾用户的正确方法
问题原因
直接用外部邮箱作为userPrincipalName并设置userType='guest'会报错,核心原因有两点:
- 来宾用户的
userPrincipalName必须遵循特定格式:外部邮箱替换@为_ + #EXT#@你的租户域名(例如kevin234_hotmail.com#EXT#@domain.onmicrosoft.com) - 来宾用户不需要设置
PasswordProfile,他们的登录凭据由外部身份提供商管理,或通过邀请链接完成设置
方法一:修正直接创建用户的代码
调整字段格式后,可通过/users端点创建来宾用户,代码示例:
User user = new User(); user.accountEnabled = true; user.displayName = "Kevin"; user.mailNickname = "kevin"; // 按规范格式设置来宾用户UPN user.userPrincipalName = "kevin234_hotmail.com#EXT#@domain.onmicrosoft.com"; user.userType = "Guest"; // 遵循Graph API规范,首字母大写 // 移除PasswordProfile字段,来宾用户无需配置 graphClient.users() .buildRequest() .post(user);
方法二:使用官方推荐的邀请API(更简便合规)
微软官方推荐使用/invitations端点创建来宾用户,该方式会自动发送邀请邮件给外部用户,用户接受后自动加入租户,流程更完整。代码示例:
Invitation invitation = new Invitation(); invitation.invitedUserEmailAddress = "kevin234@hotmail.com"; invitation.inviteRedirectUrl = "https://your-app-url.com"; // 用户接受邀请后跳转的业务地址 invitation.sendInvitationMessage = true; // 自动触发邀请邮件发送 graphClient.invitations() .buildRequest() .post(invitation);
调用该API后,外部用户会收到邀请邮件,点击链接完成身份验证后,Azure AD会自动创建对应的来宾用户账号。
内容的提问来源于stack exchange,提问作者user137062
相关产品推荐
相关产品推荐

