PowerShell创建的Azure Client Secret无法使用,门户创建的正常
解决New-AzureADApplicationPasswordCredential创建密钥报错AADSTS7000215的问题
使用命令
$appSecret = New-AzureADApplicationPasswordCredential -CustomKeyIdentifier PrimarySecret -ObjectId $app.ObjectId创建Client Secret后,调用时出现错误:
Authentication failed: AADSTS7000215: Invalid client secret provided. Ensure the secret being sent in the request is the client secret value, not the client secret ID, for a secret added to app 'xxxx'
确认已提供客户端密钥但仍报错,而通过Azure门户创建的密钥可正常使用。
- 核心问题:误用了返回对象的属性
New-AzureADApplicationPasswordCredential返回的$appSecret对象中,CustomKeyIdentifier是你指定的密钥ID(即PrimarySecret),真正的密钥值存储在Value属性里。如果错把CustomKeyIdentifier当作密钥值传入请求,就会触发这个报错。 - 正确获取密钥值的操作
执行命令后,必须提取$appSecret.Value属性的值作为实际使用的客户端密钥,示例代码:$appSecret = New-AzureADApplicationPasswordCredential -CustomKeyIdentifier PrimarySecret -ObjectId $app.ObjectId $validSecret = $appSecret.Value # 这个才是认证时需要传入的密钥 - 门户创建密钥正常的原因
在Azure门户创建密钥时,页面直接展示的是密钥的实际值,你复制的内容本身就是正确的;而PowerShell返回的对象包含多个属性,很容易混淆密钥ID和密钥值。
内容的提问来源于stack exchange,提问作者gnsharans
相关产品推荐
相关产品推荐

