使用Microsoft Graph SDK获取Group类型组成员运行报错如何解决
问题描述
我尝试仅获取目标组中类型为'Group'的成员,实现代码如下:
var _graphServiceClient = new GraphServiceClient(CreateAuthProviderFromSecret(creds)); var applicationsInGroup = await _graphServiceClient.Groups[objectId.ToString()].Members.Group.GetAsync(); public static IAuthenticationProvider CreateAuthProviderFromSecret(GraphCredentials creds) { var confidentialClientApplication = ConfidentialClientApplicationBuilder .Create(creds.ClientId) .WithTenantId(creds.TenantId) .WithClientSecret(creds.ClientSecret) .Build(); return new ClientCredentialProvider(confidentialClientApplication); }
运行上述代码时出现如下报错:
请问当前实现存在什么问题,应当如何修正?
问题原因
代码报错核心是API路由写法错误:
- Microsoft Graph的
/groups/{id}/members接口返回directoryObject类型集合,不存在/groups/{id}/members/group这个合法路由,直接调用.Members.Group.GetAsync()会请求不存在的接口,触发路由匹配错误。 - 要筛选成员中类型为组的项,不能通过拼接路径段实现,需要通过查询参数筛选成员的对象类型。
- 你实现的身份认证提供逻辑本身没有问题,不需要修改。
修正方案
使用$filter参数配合isof运算符筛选类型为组的成员,参考实现代码如下:
// 查询组成员,筛选类型为Group的项 var groupMembersResponse = await _graphServiceClient.Groups[objectId.ToString()] .Members .GetAsync(requestConfig => { // 筛选派生类型为microsoft.graph.group的对象 requestConfig.QueryParameters.Filter = "isof('microsoft.graph.group')"; // 按需指定需要返回的组属性,减少不必要的数据返回 requestConfig.QueryParameters.Select = new[] { "id", "displayName", "description" }; requestConfig.QueryParameters.Top = 999; }); List<Group> nestedGroups = new List<Group>(); // 遍历当前页结果,筛选Group类型项 if (groupMembersResponse.Value != null) { foreach (var dirObj in groupMembersResponse.Value) { if (dirObj is Group targetGroup) { nestedGroups.Add(targetGroup); } } } // 如果组成员数量较多,添加分页遍历逻辑,拉取全量结果 var pageIterator = PageIterator<DirectoryObject, DirectoryObjectCollectionResponse> .CreatePageIterator(_graphServiceClient, groupMembersResponse, (item) => { if (item is Group targetGroup) { nestedGroups.Add(targetGroup); } return true; }); await pageIterator.IterateAsync();
注意事项
- 提前给对应的Azure AD应用注册授予
GroupMember.Read.All或者Group.Read.All应用程序权限,并且完成管理员同意,否则会出现403权限不足错误。 - 如果使用的是v4及更早版本的Graph SDK,不支持Lambda方式配置查询参数的话,可以通过给请求添加QueryOption的方式传入Filter参数,筛选逻辑完全一致。
内容的提问来源于stack exchange,提问作者user989988
相关产品推荐
相关产品推荐

