You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform创建Azure AKS集群遇MFA认证错误求助

AADSTS50076错误根源解析(Terraform Azure AKS部署场景)

错误回顾

Error: building account: getting authenticated object ID: parsing json result from the Azure CLI: waiting for the Azure CLI: exit status 1: ERROR: AADSTS50076: Due to
a configuration change made by your administrator, or because you moved to a new location, you must use multi-factor authentication to access '00000003-0000-0000-c000-000000000000'.
│ Trace ID: 3391ac9b-4e8d-43a3-88f5-0cb1093a2d00
│ Correlation ID: fe984fa6-71ff-42d6-b487-7b988a7e1dd6
│ Timestamp: 2022-08-23 13:39:59Z
│ To re-authenticate, please run:
│ az login --scope https://graph.microsoft.com//.default
│
│ with provider["registry.terraform.io/hashicorp/azurerm"],
│ on tf1-provider.tf line 48, in provider "azurerm":
│ 48: provider "azurerm" {

问题根源

1. 目标资源是Microsoft Graph API

错误里的00000003-0000-0000-c000-000000000000是Microsoft Graph API的固定应用ID,Terraform的AzureRM Provider在初始化阶段,需要调用这个API获取当前认证用户的Object ID,以此构建账户上下文。

2. 普通az login的权限范围不覆盖Graph API

常规的az login默认获取的令牌仅包含Azure Resource Manager(ARM)的访问权限,未包含Microsoft Graph API的权限。当Provider尝试调用Graph API时,会触发权限校验失败。

3. 租户MFA策略强制拦截

你的Azure AD管理员已配置针对Microsoft Graph API的**强制多因素认证(MFA)**策略,任何未通过MFA验证的请求都会被拦截。之前的az login要么未完成MFA验证,要么会话中MFA状态已过期,导致请求被拒绝。

4. 指定Scope的登录是补全权限+MFA验证

错误提示的az login --scope https://graph.microsoft.com//.default命令,会强制获取针对Microsoft Graph API的全范围权限令牌,同时触发MFA验证流程。完成后,Azure CLI会话就拥有了访问Graph API的有效权限,Terraform Provider就能顺利获取用户Object ID,完成初始化。

总结

本质是Terraform AzureRM Provider依赖Microsoft Graph API获取用户信息,而你的租户要求访问该API必须通过MFA,且普通登录的权限范围不包含该API,因此必须通过指定Scope的登录完成MFA验证和权限授权。

内容的提问来源于stack exchange,提问作者VivekDev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 16:09:17