使用ClientSecretCredential获取租户拒绝分配列表时遇'signed_session'错误
解决Deny Assignments遍历中的
signed_session错误 原因分析
这个错误源于Azure SDK版本不兼容:你使用了新版azure-identity库的ClientSecretCredential,但搭配了旧版的azure-mgmt-authorization库。旧版AuthorizationManagementClient依赖ADAL(Azure Active Directory Authentication Library)的凭证接口,而新版ClientSecretCredential基于MSAL(Microsoft Authentication Library),两者接口不兼容,因此触发了signed_session属性不存在的错误。
解决方案
1. 升级兼容的Azure SDK版本
确保azure-mgmt-authorization和azure-identity版本匹配,执行以下命令升级:
pip install --upgrade azure-mgmt-authorization azure-identity
2. 修正客户端初始化代码
使用新版SDK时,AuthorizationManagementClient的初始化需传入credential和subscription_id,示例代码如下:
from azure.identity import ClientSecretCredential from azure.mgmt.authorization import AuthorizationManagementClient # 初始化凭证 credential = ClientSecretCredential( tenant_id="你的租户ID", client_id="你的客户端ID", client_secret="你的客户端密钥" ) # 遍历订阅与资源组,获取Deny Assignments for subscription_id in 订阅ID列表: auth_client = AuthorizationManagementClient(credential, subscription_id) for resource_group in 资源组列表: deny_assignments = auth_client.deny_assignments.list_for_resource_group(resource_group.name) # 正确遍历DenyAssignmentPaged对象 for assignment in deny_assignments: print(assignment.name, assignment.description)
3. 清理冲突的旧版依赖
如果升级后仍报错,检查是否安装了ADAL相关旧库(如azure.common.credentials),这类库会和新版azure-identity冲突,可执行卸载:
pip uninstall azure.common azure-nspkg azure-storage
内容的提问来源于stack exchange,提问作者gnsharans
相关产品推荐
相关产品推荐

