You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

MS Graph Webhook未接收Azure AD用户删除通知的问题求助

Troubleshooting MS Graph Webhook Not Firing for User "Deleted" Events

Let’s break down the key issues and fixes tailored to your scenario:

1. Clarify Soft- vs Hard-Delete Event Behavior

First, it’s critical to understand how MS Graph maps user deletion actions to webhook events:

  • Soft-delete (moving a user to the recycle bin): This does NOT trigger a deleted event for the users resource. Instead, this action updates the user’s accountEnabled property to false (along with other metadata), which will fire an updated event if you’ve subscribed to that ChangeType.
  • Hard-delete (permanently removing a user from the recycle bin): This is the only action that should trigger a deleted event for the users resource. Note that if your tenant uses the default delayed permanent deletion setting (30 days), manually removing a user from the recycle bin won’t immediately hard-delete them—they’ll enter a waiting period, and the deleted event will only fire once that period expires.

2. Verify Subscription Configuration Details

Double-check your active subscription to rule out simple misconfigurations:

  • Confirm the changeType is exactly set to deleted (no typos like delete). You can use Graph Explorer to list your subscriptions via the GET /subscriptions endpoint to validate this.
  • Ensure the resource is correctly set to users (not a filtered subset that excludes the users you’re testing with).

3. Confirm You’re Using Application Permissions

Webhook subscriptions for user deletion events require application permissions, not delegated permissions. Even though you have User.Read.All and Directory.Read.All, make sure these are granted as application permissions in your Azure AD app registration. Delegated permissions won’t work for background webhook subscriptions.

4. Account for Event Propagation Delay

If you’re testing by hard-deleting a user from the recycle bin, wait 5-15 minutes for the event to propagate through MS Graph. In larger tenants, there can be a small delay between the action and the webhook notification being sent.

5. Expand Subscriptions for Full Deletion Visibility

If you need to monitor both soft-delete and hard-delete actions, use a two-subscription approach:

  • Keep your updated subscription to catch soft-deletes (you can filter notifications by checking if the accountEnabled property changed to false in the payload).
  • Add a separate subscription targeting directory/deletedItems/microsoft.graph.user with changeType=deleted—this will notify you when a user is permanently deleted, either after the delayed period or via immediate hard-delete if your tenant is configured that way.

内容的提问来源于stack exchange,提问作者Christian

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 05:30:39