如何通过PowerShell无交互为Azure AD应用授予GraphAPI权限管理员同意
无交互授予Azure AD应用Graph API管理员同意的解决方案
首先得明确:你用的https://login.microsoftonline.com/{tenant}/v2.0/adminconsent这个端点是交互式管理员同意流程,设计上就是要引导管理员通过浏览器登录授权,所以直接发GET请求返回登录页面HTML是完全正常的,没法用它来实现无交互的同意操作。
针对Azure Runbook这种无交互场景,推荐两种可行的方案:
方案1:使用Microsoft Graph PowerShell模块(推荐)
这个模块是微软目前主推的,功能更全面,适合自动化场景。
步骤:
导入模块(Runbook中需确保已安装)
如果你的Azure自动化账户还没装这个模块,先在自动化账户的「模块」里添加Microsoft.Graph,或者在Runbook开头执行:Install-Module Microsoft.Graph -Force -AllowClobber -Scope CurrentUser Import-Module Microsoft.Graph.Identity.SignIns用全局管理员权限的服务主体登录
你需要一个拥有全局管理员/云应用管理员/应用程序管理员角色的服务主体(安全起见,优先用服务主体而非用户名密码),把它的客户端ID、密钥、租户ID存在自动化账户的「凭据」资产里,然后调用:$cred = Get-AutomationPSCredential -Name "你的全局管理员服务主体凭据" $tenantId = "你的租户ID" Connect-MgGraph -TenantId $tenantId -ClientSecretCredential $cred授予应用权限(针对应用权限类型)
如果你的Graph API权限是应用权限(非委托权限),执行以下代码:# 目标应用的客户端ID $targetAppId = "6731de76-14a6-49ae-97bc-6eba6914391e" $targetSp = Get-MgServicePrincipal -Filter "appId eq '$targetAppId'" # Graph API的服务主体ID固定为00000003-0000-0000-c000-000000000000 $graphSp = Get-MgServicePrincipal -Filter "appId eq '00000003-0000-0000-c000-000000000000'" # 获取需要的应用权限ID(可以提前查好,或者动态获取) $calendarsReadRole = $graphSp.AppRoles | Where-Object { $_.Value -eq "Calendars.Read" } $mailSendRole = $graphSp.AppRoles | Where-Object { $_.Value -eq "Mail.Send" } # 添加角色分配 New-MgServicePrincipalAppRoleAssignment -ServicePrincipalId $targetSp.Id ` -PrincipalId $targetSp.Id ` -ResourceId $graphSp.Id ` -AppRoleId $calendarsReadRole.Id New-MgServicePrincipalAppRoleAssignment -ServicePrincipalId $targetSp.Id ` -PrincipalId $targetSp.Id ` -ResourceId $graphSp.Id ` -AppRoleId $mailSendRole.Id授予委托权限的管理员同意(如果是委托权限)
要是你需要授予的是委托权限,用下面的代码:$oauthPermissionGrant = @{ ClientId = $targetSp.Id ConsentType = "AllPrincipals" # 表示所有用户都能使用该权限 ResourceId = $graphSp.Id Scope = "calendars.read mail.send" } New-MgOauth2PermissionGrant -BodyParameter $oauthPermissionGrant
方案2:使用AzureAD PowerShell模块
如果习惯用旧的AzureAD模块,也可以这么操作:
步骤:
登录服务主体
$cred = Get-AutomationPSCredential -Name "你的全局管理员服务主体凭据" $tenantId = "你的租户ID" Connect-AzureAD -TenantId $tenantId -ApplicationId $cred.UserName -Credential $cred授予应用权限
$targetSp = Get-AzureADServicePrincipal -Filter "AppId eq '6731de76-14a6-49ae-97bc-6eba6914391e'" $graphSp = Get-AzureADServicePrincipal -Filter "AppId eq '00000003-0000-0000-c000-000000000000'" $calendarsReadRole = $graphSp.AppRoles | Where-Object { $_.Value -eq "Calendars.Read" } $mailSendRole = $graphSp.AppRoles | Where-Object { $_.Value -eq "Mail.Send" } New-AzureADServicePrincipalAppRoleAssignment -ObjectId $targetSp.ObjectId ` -PrincipalId $targetSp.ObjectId ` -ResourceId $graphSp.ObjectId ` -Id $calendarsReadRole.Id New-AzureADServicePrincipalAppRoleAssignment -ObjectId $targetSp.ObjectId ` -PrincipalId $targetSp.ObjectId ` -ResourceId $graphSp.ObjectId ` -Id $mailSendRole.Id授予委托权限的管理员同意
New-AzureADOAuth2PermissionGrant -ResourceId $graphSp.ObjectId ` -ClientId $targetSp.ObjectId ` -Scope "calendars.read mail.send" ` -ConsentType "AllPrincipals"
关键注意事项
- 用于登录的服务主体必须拥有全局管理员、云应用管理员或应用程序管理员角色,否则没有权限授予管理员同意。
- 在Runbook中,绝对不要明文写服务主体的密钥,一定要用自动化账户的「凭据」资产存储,通过
Get-AutomationPSCredential调用。 - 权限ID可以通过PowerShell提前查询,比如执行
Get-MgServicePrincipal -AppId "00000003-0000-0000-c000-000000000000" | Select-Object -ExpandProperty AppRoles就能看到所有Graph API的应用权限及其ID。
内容的提问来源于stack exchange,提问作者Redman
相关产品推荐
相关产品推荐

