如何在Powershell 7.2下不使用AzureAD模块执行Azure AD应用注册
基于Microsoft Graph PowerShell SDK的跨平台实现方案
模块适配说明
原AzureAD模块仅支持Windows PowerShell,Microsoft Graph PowerShell SDK是官方推出的跨平台替代方案,完美适配PowerShell 7.x和Linux环境。你提到的clientId仅在应用身份认证场景下需要,使用全局管理员账号的委托认证场景无需提前准备clientId。
步骤1:安装所需模块
在PowerShell 7.2中执行以下命令安装最小依赖模块:
Install-Module Microsoft.Graph.Authentication, Microsoft.Graph.Applications -Scope CurrentUser -Force
步骤2:适配后的完整代码
可直接替换你原有AzureAD逻辑:
# 认证信息配置 $tenantId = "abcdef12345-1234-1234-124-abcdef12346789" $account = "my_admin@domain.com" $password = ConvertTo-SecureString "MyPassword" -AsPlainText -Force $psCred = New-Object System.Management.Automation.PSCredential -ArgumentList ($account, $password) # 连接Microsoft Graph,申请创建应用所需权限 Connect-MgGraph -Credential $psCred -TenantId $tenantId -Scopes "Application.ReadWrite.All" # 创建应用注册 $appName = "MyApp" $newApp = New-MgApplication -DisplayName $appName # 输出创建完成的应用信息,可按需取用 Write-Host "应用创建成功,应用ID:" $newApp.AppId Write-Host "应用对象ID:" $newApp.Id
权限说明
首次执行时因为你的账号是全局管理员,会自动同意权限申请,流水线场景下首次运行一次完成权限授权后,后续即可无交互运行。
内容的提问来源于stack exchange,提问作者Alexminer
相关产品推荐
相关产品推荐

