MS Graph Webhook未接收Azure AD用户删除通知的问题求助
Let’s break down the key issues and fixes tailored to your scenario:
1. Clarify Soft- vs Hard-Delete Event Behavior
First, it’s critical to understand how MS Graph maps user deletion actions to webhook events:
- Soft-delete (moving a user to the recycle bin): This does NOT trigger a
deletedevent for theusersresource. Instead, this action updates the user’saccountEnabledproperty tofalse(along with other metadata), which will fire anupdatedevent if you’ve subscribed to that ChangeType. - Hard-delete (permanently removing a user from the recycle bin): This is the only action that should trigger a
deletedevent for theusersresource. Note that if your tenant uses the default delayed permanent deletion setting (30 days), manually removing a user from the recycle bin won’t immediately hard-delete them—they’ll enter a waiting period, and thedeletedevent will only fire once that period expires.
2. Verify Subscription Configuration Details
Double-check your active subscription to rule out simple misconfigurations:
- Confirm the
changeTypeis exactly set todeleted(no typos likedelete). You can use Graph Explorer to list your subscriptions via theGET /subscriptionsendpoint to validate this. - Ensure the
resourceis correctly set tousers(not a filtered subset that excludes the users you’re testing with).
3. Confirm You’re Using Application Permissions
Webhook subscriptions for user deletion events require application permissions, not delegated permissions. Even though you have User.Read.All and Directory.Read.All, make sure these are granted as application permissions in your Azure AD app registration. Delegated permissions won’t work for background webhook subscriptions.
4. Account for Event Propagation Delay
If you’re testing by hard-deleting a user from the recycle bin, wait 5-15 minutes for the event to propagate through MS Graph. In larger tenants, there can be a small delay between the action and the webhook notification being sent.
5. Expand Subscriptions for Full Deletion Visibility
If you need to monitor both soft-delete and hard-delete actions, use a two-subscription approach:
- Keep your
updatedsubscription to catch soft-deletes (you can filter notifications by checking if theaccountEnabledproperty changed tofalsein the payload). - Add a separate subscription targeting
directory/deletedItems/microsoft.graph.userwithchangeType=deleted—this will notify you when a user is permanently deleted, either after the delayed period or via immediate hard-delete if your tenant is configured that way.
内容的提问来源于stack exchange,提问作者Christian

