Get-AzureADApplicationPasswordCredential cmdlet返回value字段为空,求助解决
I've run into this exact confusion before, so I can clarify what's going on here:
The Get-AzureADApplicationPasswordCredential cmdlet will never return a populated Value field for existing password credentials—this is by design for security reasons. Azure AD does not store the plaintext version of password credentials once they're created; it only stores a hashed representation.
Here's the key context you need:
- When you first create a password credential using
New-AzureADApplicationPasswordCredential, the cmdlet returns the plaintextValueonly once. You must save this value immediately, because you'll never be able to retrieve it from Azure AD again. - The
Get-AzureADApplicationPasswordCredentialcmdlet is meant to return metadata about existing credentials (likeKeyId,StartDate,EndDate, andCustomKeyIdentifier), not the actual secret value.
To test this, try creating a new credential and capturing the value right away:
# Replace with your app's Object ID $appObjectId = "your-app-object-id-here" $newCredential = New-AzureADApplicationPasswordCredential -ObjectId $appObjectId # This will show you the plaintext value (only available at creation time) Write-Host "New password credential value: $($newCredential.Value)" # Now retrieve the credentials again $existingCredentials = Get-AzureADApplicationPasswordCredential -ObjectId $appObjectId # Check the Value field—it will be empty for all existing credentials $existingCredentials | Select-Object KeyId, Value, EndDate
So to answer your question directly: No, no one can retrieve the Value field for existing password credentials using this cmdlet. The official documentation might be a bit misleading here, but the security design takes precedence—Azure AD doesn't allow retrieving secrets after they're created.
内容的提问来源于stack exchange,提问作者Nakah

