OAuth2 v2.0中跨账户访问Azure虚拟机的正确Scope设置咨询
Got it, let's break this down clearly for you. When using Azure AD OAuth 2.0 v2.0 endpoints to grant an app access to VM operations in another account, you’re right to focus on scopes instead of the old resource parameter. Here’s exactly what you need:
First, a quick clarification: The RBAC resource provider operations documentation you referenced is actually relevant—we just need to translate those permissions into the v2.0 scope format correctly. Azure management operations (like VM start/stop/list) tie directly to RBAC actions, which become the basis for your v2.0 scopes.
Required Scopes by Operation
Each scope follows the pattern: https://management.azure.com/<resource-path>/<permission>
1. List Virtual Machines
To let the app list VMs (read-only access), use the read permission for virtual machines. For least-privilege security, narrow the scope to the specific resource group or subscription:
- Resource group-specific:
https://management.azure.com/subscriptions/{SUBSCRIPTION_ID}/resourceGroups/{RESOURCE_GROUP_NAME}/providers/Microsoft.Compute/virtualMachines/read - Subscription-wide read access:
https://management.azure.com/subscriptions/{SUBSCRIPTION_ID}/read(covers all read operations in the subscription, not just VMs)
2. Start/Stop Virtual Machines
For control actions, map directly to the specific RBAC actions for VM power operations:
- Start a VM:
https://management.azure.com/subscriptions/{SUBSCRIPTION_ID}/resourceGroups/{RESOURCE_GROUP_NAME}/providers/Microsoft.Compute/virtualMachines/start/action - Stop (deallocate) a VM:
https://management.azure.com/subscriptions/{SUBSCRIPTION_ID}/resourceGroups/{RESOURCE_GROUP_NAME}/providers/Microsoft.Compute/virtualMachines/deallocate/action - If you need both start and stop permissions, you can include both scopes in your authorization request, or use a broader (but less secure) scope:
https://management.azure.com/subscriptions/{SUBSCRIPTION_ID}/resourceGroups/{RESOURCE_GROUP_NAME}/providers/Microsoft.Compute/virtualMachines/*/action
Critical Reminders
- RBAC Role Assignment: Your app’s service principal (or the user delegating access) must be assigned an Azure RBAC role that includes these permissions on the target subscription/resource group. The built-in Virtual Machine Contributor role covers all standard VM management actions, or you can create a custom role with only the exact permissions you need.
- Scope Prefix: Always use the full
https://management.azure.com/prefix for v2.0 scopes—avoid the legacyhttps://management.core.windows.net/resource format.
内容的提问来源于stack exchange,提问作者Roman Alekseiev

