如何通过用户认证连接Azure Media Services v3 API(无弹窗)
Great question! Since you're building a CLI tool and need silent user authentication (leveraging your synced Windows AD/Azure AD identity without popups), here's how to get this working with the Azure Media Services v3 SDK:
Option 1: Using ADAL (matches your existing code style)
First, ensure you have the Microsoft.IdentityModel.Clients.ActiveDirectory NuGet package installed. Instead of ApplicationTokenProvider (designed for service principals), use UserTokenProvider with an integrated Windows authentication credential to automatically use your current logged-in domain user identity:
using Microsoft.IdentityModel.Clients.ActiveDirectory; using Microsoft.Azure.Management.Media; // Your configuration values var config = new { AadTenantId = "your-azure-ad-tenant-id", AadClientId = "your-app-registration-client-id", ArmEndpoint = "https://management.azure.com/" // Use regional endpoint if needed }; // Use integrated Windows auth to silently pick up the current domain user var userCredential = new IntegratedWindowsAuthenticationCredential( config.AadTenantId, config.AadClientId, ActiveDirectoryServiceSettings.Azure ); // Fetch user-specific authentication credentials var credentials = await UserTokenProvider.LoginSilentAsync( config.AadTenantId, userCredential ); // Initialize the AMS client with user credentials var amsClient = new AzureMediaServicesClient(config.ArmEndpoint, credentials);
Option 2: Using MSAL (modern, recommended approach)
ADAL is deprecated, so Microsoft recommends using the MSAL library (Microsoft.Identity.Client) for all new auth scenarios. Here's how to achieve silent user authentication with MSAL:
using Microsoft.Identity.Client; using Microsoft.Azure.Management.Media; using Microsoft.Rest; var config = new { AadTenantId = "your-azure-ad-tenant-id", AadClientId = "your-app-registration-client-id", ArmEndpoint = "https://management.azure.com/" }; // Create a public client application (appropriate for CLI tools) var pca = PublicClientApplicationBuilder .Create(config.AadClientId) .WithTenantId(config.AadTenantId) .Build(); // Define the required scope for Azure Media Services var scopes = new[] { $"{config.ArmEndpoint}/.default" }; // Acquire token silently using integrated Windows authentication var authResult = await pca.AcquireTokenByIntegratedWindowsAuth(scopes).ExecuteAsync(); // Convert the MSAL token to a ServiceClientCredentials instance var credentials = new TokenCredentials(authResult.AccessToken); // Initialize the AMS client var amsClient = new AzureMediaServicesClient(config.ArmEndpoint, credentials);
Critical Setup Notes
- App Registration Configuration: Your Azure AD app registration must be marked as a Public Client (CLI tools don't have a secure secret storage mechanism). In the Azure Portal, go to your app registration > Authentication > Advanced settings, then set "Allow public client flows" to Yes.
- User Permissions: Ensure the logged-in user has appropriate roles assigned to the Azure Media Services account (e.g.,
Media Services ContributororContributorat the account/resource group level) to perform the required operations. - Silent Auth Requirements: For integrated Windows auth to work without popups, the user must be logged into a domain-joined machine, and Windows AD must be synced with Azure AD (which you already have configured).
This approach will let you authenticate as the current user seamlessly, perfect for your command-line tool use case.
内容的提问来源于stack exchange,提问作者Code Monkey

