You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform配置Azure AD应用注册时Application ID URI报错问询

报错原因说明

该报错是新版Azure AD Provider(v2.0及以上版本)的校验规则变更导致的。
旧版Provider以及Azure门户手动配置时,对应用ID URI的格式校验宽松,允许直接使用非租户验证域名的HTTPS地址;但新版Provider对齐了Azure AD的底层API限制:自定义应用ID URI的域名部分必须是当前Azure AD租户下已完成所有权验证的自定义域名,azurewebsites.net属于Azure官方托管的公共域名,无法在个人租户下完成验证,因此触发配置报错。

「Expose an API」板块正确配置方案

方案1(推荐,无额外前置操作)

使用Azure AD默认的应用ID URI格式api://<应用注册客户端ID>,无需域名验证即可直接配置,对应的Terraform示例代码如下:

# 生成作用域唯一ID
resource "random_uuid" "api_user_impersonation_scope" {}

resource "azuread_application" "coalsa_api" {
  display_name = "Coalsa-API-App"

  # 配置默认格式的应用ID URI
  identifier_uris = ["api://${azuread_application.coalsa_api.client_id}"]

  # 配置暴露的API作用域
  api {
    oauth2_permission_scope {
      admin_consent_description  = "Allow full access to the Coalsa API"
      admin_consent_display_name = "Full access to Coalsa API"
      enabled                    = true
      id                         = random_uuid.api_user_impersonation_scope.result
      type                       = "User"
      user_consent_description   = "Allow the application to access Coalsa API on your behalf"
      user_consent_display_name  = "Access Coalsa API"
      value                      = "user_impersonation"
    }
  }
}

方案2(适配自定义HTTPS URI需求)

如果业务必须使用HTTPS格式的应用ID URI,需要先完成以下前置操作再配置Terraform:

  • 进入Azure AD租户的「自定义域名」板块,添加你要使用的URI对应的根域名(例如要使用https://api.your-custom-domain.com,就添加your-custom-domain.com)
  • 按照Azure提示在你的域名解析服务商添加对应的TXT验证记录,完成域名所有权验证
  • 再在Terraform的identifier_uris参数中填写你的HTTPS格式URI即可通过校验。

临时兼容方案(不推荐长期使用)

如果需要对齐之前手动配置的https://app-coalsa-api.azurewebsites.net格式URI,可以将Azure AD Provider版本降级到1.6.0之前的版本,跳过新版校验规则,旧版本不再提供功能更新和安全补丁,仅可作为临时过渡使用。


内容的提问来源于stack exchange,提问作者Pallab

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.24 14:36:07