You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OAuth2 v2.0中跨账户访问Azure虚拟机的正确Scope设置咨询

Got it, let's break this down clearly for you. When using Azure AD OAuth 2.0 v2.0 endpoints to grant an app access to VM operations in another account, you’re right to focus on scopes instead of the old resource parameter. Here’s exactly what you need:

Azure OAuth 2.0 v2.0 Scopes for VM Operations

First, a quick clarification: The RBAC resource provider operations documentation you referenced is actually relevant—we just need to translate those permissions into the v2.0 scope format correctly. Azure management operations (like VM start/stop/list) tie directly to RBAC actions, which become the basis for your v2.0 scopes.

Required Scopes by Operation

Each scope follows the pattern: https://management.azure.com/<resource-path>/<permission>

1. List Virtual Machines

To let the app list VMs (read-only access), use the read permission for virtual machines. For least-privilege security, narrow the scope to the specific resource group or subscription:

  • Resource group-specific: https://management.azure.com/subscriptions/{SUBSCRIPTION_ID}/resourceGroups/{RESOURCE_GROUP_NAME}/providers/Microsoft.Compute/virtualMachines/read
  • Subscription-wide read access: https://management.azure.com/subscriptions/{SUBSCRIPTION_ID}/read (covers all read operations in the subscription, not just VMs)

2. Start/Stop Virtual Machines

For control actions, map directly to the specific RBAC actions for VM power operations:

  • Start a VM: https://management.azure.com/subscriptions/{SUBSCRIPTION_ID}/resourceGroups/{RESOURCE_GROUP_NAME}/providers/Microsoft.Compute/virtualMachines/start/action
  • Stop (deallocate) a VM: https://management.azure.com/subscriptions/{SUBSCRIPTION_ID}/resourceGroups/{RESOURCE_GROUP_NAME}/providers/Microsoft.Compute/virtualMachines/deallocate/action
  • If you need both start and stop permissions, you can include both scopes in your authorization request, or use a broader (but less secure) scope: https://management.azure.com/subscriptions/{SUBSCRIPTION_ID}/resourceGroups/{RESOURCE_GROUP_NAME}/providers/Microsoft.Compute/virtualMachines/*/action

Critical Reminders

  • RBAC Role Assignment: Your app’s service principal (or the user delegating access) must be assigned an Azure RBAC role that includes these permissions on the target subscription/resource group. The built-in Virtual Machine Contributor role covers all standard VM management actions, or you can create a custom role with only the exact permissions you need.
  • Scope Prefix: Always use the full https://management.azure.com/ prefix for v2.0 scopes—avoid the legacy https://management.core.windows.net/ resource format.

内容的提问来源于stack exchange,提问作者Roman Alekseiev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 07:20:14