You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Microsoft Graph Java SDK创建Azure AD来宾用户?

创建Azure AD来宾用户的正确方法

问题原因

直接用外部邮箱作为userPrincipalName并设置userType='guest'会报错,核心原因有两点:

  • 来宾用户的userPrincipalName必须遵循特定格式:外部邮箱替换@为_ + #EXT#@你的租户域名(例如kevin234_hotmail.com#EXT#@domain.onmicrosoft.com)
  • 来宾用户不需要设置PasswordProfile,他们的登录凭据由外部身份提供商管理,或通过邀请链接完成设置

方法一:修正直接创建用户的代码

调整字段格式后,可通过/users端点创建来宾用户,代码示例:

User user = new User();
user.accountEnabled = true;
user.displayName = "Kevin";
user.mailNickname = "kevin";
// 按规范格式设置来宾用户UPN
user.userPrincipalName = "kevin234_hotmail.com#EXT#@domain.onmicrosoft.com";
user.userType = "Guest"; // 遵循Graph API规范,首字母大写
// 移除PasswordProfile字段,来宾用户无需配置

graphClient.users()
    .buildRequest()
    .post(user);

方法二:使用官方推荐的邀请API(更简便合规)

微软官方推荐使用/invitations端点创建来宾用户,该方式会自动发送邀请邮件给外部用户,用户接受后自动加入租户,流程更完整。代码示例:

Invitation invitation = new Invitation();
invitation.invitedUserEmailAddress = "kevin234@hotmail.com";
invitation.inviteRedirectUrl = "https://your-app-url.com"; // 用户接受邀请后跳转的业务地址
invitation.sendInvitationMessage = true; // 自动触发邀请邮件发送

graphClient.invitations()
    .buildRequest()
    .post(invitation);

调用该API后,外部用户会收到邀请邮件,点击链接完成身份验证后,Azure AD会自动创建对应的来宾用户账号。

内容的提问来源于stack exchange,提问作者user137062

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 14:18:25