You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨租户订阅场景下如何获取有效的Access Token?

跨Azure AD租户查询Log Analytics Workspace的认证问题

问题场景

尝试在Power Automate中用"Invoke an HTTP request"或"Run query and list results"操作查询另一个AAD租户下的Log Analytics Workspace(已通过Azure Portal有权访问),但执行时返回认证错误:

错误截图

完整错误信息:

{
  "error": {
    "message": "The provided authentication is not valid for this resource",
    "code": "InvalidTokenError",
    "correlationId": "45e0ff0c-01f1-4ea5-a11d-ec6ce2d71b8b",
    "innererror": {
      "code": "InvalidAuthenticationTokenTenant",
      "message": "The access token is from the wrong issuer 'https://sts.windows.net/687f51c3-0c5d-4905-84f8-97c683a5b9d1/'. It must match one of the tenants 'https://sts.windows.net/2f4a9838-26b7-47ee-be60-ccc1fdec5953/,https://sts.windows.net/a6eb2ff5-3009-4bfc-b769-24a2f82c1913/' associated with this subscription. Please use any authority (URL) from 'https://login.windows.net/2f4a9838-26b7-47ee-be60-ccc1fdec5953,https://login.windows.net/a6eb2ff5-3009-4bfc-b769-24a2f82c1913' to get the token. Note, if the subscription is transferred to another tenant there is no impact to the services, but information about new tenant could take time to propagate (up to an hour). If you just transferred your subscription and see this error message, please try back later."
    }
  }
}

错误原因

Power Automate默认使用当前环境所属租户的身份令牌,但目标Log Analytics Workspace属于另一个AAD租户,令牌的签发租户与资源所属租户不匹配,导致认证失败。

解决方案

方法1:配置HTTP请求的跨租户认证(针对"Invoke an HTTP request"操作)

  • 打开HTTP操作的Authentication设置,选择Active Directory OAuth
  • 填写以下参数:
    • Tenant:填入错误信息中指定的目标租户ID(选对应Workspace所属的租户,比如2f4a9838-26b7-47ee-be60-ccc1fdec5953)
    • Audience:固定填https://api.loganalytics.io
    • Client ID:
      • 若使用托管身份:需将Power Automate环境的托管身份在目标租户中添加为Log Analytics Workspace的Log Analytics Reader角色成员
      • 若使用服务主体:在目标租户注册服务主体,授予Log Analytics Reader权限,填入该服务主体的Client ID
    • Credentials:使用服务主体时填入其密钥/证书,使用托管身份时留空

方法2:修复内置查询操作的租户关联(针对"Run query and list results"操作)

  • 在操作的Workspace选择框中,点击顶部的租户下拉菜单,切换到目标租户
  • 若看不到目标Workspace,执行以下步骤:
    1. 确认你的账号在目标租户拥有Log Analytics Reader权限
    2. 点击操作中的Connect按钮,选择Connect with a different account,用有权访问目标租户的账号登录,重新选择Workspace

通用权限验证

无论采用哪种方法,必须确保:

  • 用于认证的身份(个人账号/服务主体/托管身份)在目标租户的Log Analytics Workspace上被明确授予Log Analytics Reader或更高权限(如Contributor)
  • 若使用托管身份,需在目标租户的Azure Portal中,进入Workspace的**Access control (IAM)**页面,添加托管身份为对应角色的成员

内容的提问来源于stack exchange,提问作者Robin Roy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 16:24:31