You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell无交互为Azure AD应用授予GraphAPI权限管理员同意

无交互授予Azure AD应用Graph API管理员同意的解决方案

首先得明确:你用的https://login.microsoftonline.com/{tenant}/v2.0/adminconsent这个端点是交互式管理员同意流程,设计上就是要引导管理员通过浏览器登录授权,所以直接发GET请求返回登录页面HTML是完全正常的,没法用它来实现无交互的同意操作。

针对Azure Runbook这种无交互场景,推荐两种可行的方案:

方案1:使用Microsoft Graph PowerShell模块(推荐)

这个模块是微软目前主推的,功能更全面,适合自动化场景。

步骤:

  1. 导入模块(Runbook中需确保已安装)
    如果你的Azure自动化账户还没装这个模块,先在自动化账户的「模块」里添加Microsoft.Graph,或者在Runbook开头执行:

    Install-Module Microsoft.Graph -Force -AllowClobber -Scope CurrentUser
    Import-Module Microsoft.Graph.Identity.SignIns
    
  2. 用全局管理员权限的服务主体登录
    你需要一个拥有全局管理员/云应用管理员/应用程序管理员角色的服务主体(安全起见,优先用服务主体而非用户名密码),把它的客户端ID、密钥、租户ID存在自动化账户的「凭据」资产里,然后调用:

    $cred = Get-AutomationPSCredential -Name "你的全局管理员服务主体凭据"
    $tenantId = "你的租户ID"
    
    Connect-MgGraph -TenantId $tenantId -ClientSecretCredential $cred
    
  3. 授予应用权限(针对应用权限类型)
    如果你的Graph API权限是应用权限(非委托权限),执行以下代码:

    # 目标应用的客户端ID
    $targetAppId = "6731de76-14a6-49ae-97bc-6eba6914391e"
    $targetSp = Get-MgServicePrincipal -Filter "appId eq '$targetAppId'"
    # Graph API的服务主体ID固定为00000003-0000-0000-c000-000000000000
    $graphSp = Get-MgServicePrincipal -Filter "appId eq '00000003-0000-0000-c000-000000000000'"
    
    # 获取需要的应用权限ID(可以提前查好,或者动态获取)
    $calendarsReadRole = $graphSp.AppRoles | Where-Object { $_.Value -eq "Calendars.Read" }
    $mailSendRole = $graphSp.AppRoles | Where-Object { $_.Value -eq "Mail.Send" }
    
    # 添加角色分配
    New-MgServicePrincipalAppRoleAssignment -ServicePrincipalId $targetSp.Id `
        -PrincipalId $targetSp.Id `
        -ResourceId $graphSp.Id `
        -AppRoleId $calendarsReadRole.Id
    
    New-MgServicePrincipalAppRoleAssignment -ServicePrincipalId $targetSp.Id `
        -PrincipalId $targetSp.Id `
        -ResourceId $graphSp.Id `
        -AppRoleId $mailSendRole.Id
    
  4. 授予委托权限的管理员同意(如果是委托权限)
    要是你需要授予的是委托权限,用下面的代码:

    $oauthPermissionGrant = @{
        ClientId = $targetSp.Id
        ConsentType = "AllPrincipals" # 表示所有用户都能使用该权限
        ResourceId = $graphSp.Id
        Scope = "calendars.read mail.send"
    }
    
    New-MgOauth2PermissionGrant -BodyParameter $oauthPermissionGrant
    

方案2:使用AzureAD PowerShell模块

如果习惯用旧的AzureAD模块,也可以这么操作:

步骤:

  1. 登录服务主体

    $cred = Get-AutomationPSCredential -Name "你的全局管理员服务主体凭据"
    $tenantId = "你的租户ID"
    
    Connect-AzureAD -TenantId $tenantId -ApplicationId $cred.UserName -Credential $cred
    
  2. 授予应用权限

    $targetSp = Get-AzureADServicePrincipal -Filter "AppId eq '6731de76-14a6-49ae-97bc-6eba6914391e'"
    $graphSp = Get-AzureADServicePrincipal -Filter "AppId eq '00000003-0000-0000-c000-000000000000'"
    
    $calendarsReadRole = $graphSp.AppRoles | Where-Object { $_.Value -eq "Calendars.Read" }
    $mailSendRole = $graphSp.AppRoles | Where-Object { $_.Value -eq "Mail.Send" }
    
    New-AzureADServicePrincipalAppRoleAssignment -ObjectId $targetSp.ObjectId `
        -PrincipalId $targetSp.ObjectId `
        -ResourceId $graphSp.ObjectId `
        -Id $calendarsReadRole.Id
    
    New-AzureADServicePrincipalAppRoleAssignment -ObjectId $targetSp.ObjectId `
        -PrincipalId $targetSp.ObjectId `
        -ResourceId $graphSp.ObjectId `
        -Id $mailSendRole.Id
    
  3. 授予委托权限的管理员同意

    New-AzureADOAuth2PermissionGrant -ResourceId $graphSp.ObjectId `
        -ClientId $targetSp.ObjectId `
        -Scope "calendars.read mail.send" `
        -ConsentType "AllPrincipals"
    

关键注意事项

  • 用于登录的服务主体必须拥有全局管理员、云应用管理员或应用程序管理员角色,否则没有权限授予管理员同意。
  • 在Runbook中,绝对不要明文写服务主体的密钥,一定要用自动化账户的「凭据」资产存储,通过Get-AutomationPSCredential调用。
  • 权限ID可以通过PowerShell提前查询,比如执行Get-MgServicePrincipal -AppId "00000003-0000-0000-c000-000000000000" | Select-Object -ExpandProperty AppRoles就能看到所有Graph API的应用权限及其ID。

内容的提问来源于stack exchange,提问作者Redman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 18:37:56