You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用ClientSecretCredential获取租户拒绝分配列表时遇'signed_session'错误

解决Deny Assignments遍历中的signed_session错误

原因分析

这个错误源于Azure SDK版本不兼容:你使用了新版azure-identity库的ClientSecretCredential,但搭配了旧版的azure-mgmt-authorization库。旧版AuthorizationManagementClient依赖ADAL(Azure Active Directory Authentication Library)的凭证接口,而新版ClientSecretCredential基于MSAL(Microsoft Authentication Library),两者接口不兼容,因此触发了signed_session属性不存在的错误。

解决方案

1. 升级兼容的Azure SDK版本

确保azure-mgmt-authorization和azure-identity版本匹配,执行以下命令升级:

pip install --upgrade azure-mgmt-authorization azure-identity

2. 修正客户端初始化代码

使用新版SDK时,AuthorizationManagementClient的初始化需传入credential和subscription_id,示例代码如下:

from azure.identity import ClientSecretCredential
from azure.mgmt.authorization import AuthorizationManagementClient

# 初始化凭证
credential = ClientSecretCredential(
    tenant_id="你的租户ID",
    client_id="你的客户端ID",
    client_secret="你的客户端密钥"
)

# 遍历订阅与资源组,获取Deny Assignments
for subscription_id in 订阅ID列表:
    auth_client = AuthorizationManagementClient(credential, subscription_id)
    for resource_group in 资源组列表:
        deny_assignments = auth_client.deny_assignments.list_for_resource_group(resource_group.name)
        # 正确遍历DenyAssignmentPaged对象
        for assignment in deny_assignments:
            print(assignment.name, assignment.description)

3. 清理冲突的旧版依赖

如果升级后仍报错,检查是否安装了ADAL相关旧库(如azure.common.credentials),这类库会和新版azure-identity冲突,可执行卸载:

pip uninstall azure.common azure-nspkg azure-storage

内容的提问来源于stack exchange,提问作者gnsharans

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 06:54:05