You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Microsoft.Graph.Beta SDK创建Teams会议遇AAD用户查找失败错误

修复Microsoft Graph Beta SDK创建Teams会议时的"User lookup by user id failed in AAD"错误

这个错误的核心原因很明确——你用了**客户端凭证流(Client Credential Flow)**来调用Graph API,但却使用了Me这个依赖用户上下文的端点,而客户端凭证流是基于应用身份运行的,没有绑定任何具体用户,所以Graph API找不到对应的用户,就抛出了"User lookup by user id failed in AAD"的错误。

下面是具体的修复步骤:

1. 厘清身份流的差异

客户端凭证流是给无用户交互的服务端应用设计的,完全以应用自身的身份访问资源;而Me端点仅适用于委派权限流(比如用户登录的场景),它依赖当前登录用户的上下文。所以你不能在客户端凭证流里使用Me。

2. 修改API调用逻辑

要创建Teams会议,你需要指定一个具体的用户(该用户必须拥有Teams许可证),用Users端点替代Me。修改你的CreateTeamsMeeting方法:

public static async Task<OnlineMeeting> CreateTeamsMeeting(IAuthenticationProvider authProvider, string userIdOrUpn) {
    GraphServiceClient graphClient = new GraphServiceClient(authProvider);
    var onlineMeeting = new OnlineMeeting {
        StartDateTime = DateTimeOffset.Parse("2020-11-12T21:30:34.2444915+00:00"),
        EndDateTime = DateTimeOffset.Parse("2020-11-12T22:00:34.2464912+00:00"),
        Subject = "App Identity Meeting",
    };
    // 替换Me为指定用户的ID或UPN(用户主体名,比如user@yourtenant.onmicrosoft.com)
    return await graphClient.Users[userIdOrUpn].OnlineMeetings
        .Request()
        .AddAsync(onlineMeeting);
}

然后在Main方法中调用时,传入目标用户的ID或UPN:

static void Main(string[] args) {
    var clientId = "<Enter you Client ID here>";
    var tenantId = "<Enter your tenand ID here>";
    var clientSecret = "<Enter your client secret here>";
    var scopes = new string[] { "https://graph.microsoft.com/.default" };

    IConfidentialClientApplication confidentialClientApplication = ConfidentialClientApplicationBuilder
        .Create(clientId)
        .WithTenantId(tenantId)
        .WithClientSecret(clientSecret)
        .Build();
    ClientCredentialProvider authProvider = new ClientCredentialProvider(confidentialClientApplication);
    
    // 替换成你的目标用户ID或UPN
    var targetUser = "user@yourtenant.onmicrosoft.com";
    var onlinemeeting = CreateTeamsMeeting(authProvider, targetUser).GetAwaiter().GetResult();
    Console.ReadLine();
}

3. 配置正确的应用权限

因为使用的是客户端凭证流,你需要在Azure AD应用注册中添加应用权限(而非委派权限):

  • 进入你的应用注册页面 → 权限 → 添加权限 → Microsoft Graph → 应用权限
  • 搜索并添加OnlineMeetings.ReadWrite.All权限
  • 点击"授予管理员同意"(必须由全局管理员操作)

4. 额外注意事项

  • 确保指定的目标用户拥有Microsoft Teams许可证,否则无法成功创建会议
  • 若需要动态选择用户,可先通过Graph API查询租户内的用户列表,再获取对应的ID/UPN用于创建会议

内容的提问来源于stack exchange,提问作者Ali Asad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 20:17:33