You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Selenium启动Chrome操作Azure VM启用复制时遇AzureAD条件访问登录报错

Selenium启动Chrome访问Azure门户触发条件访问53000错误解决方案

根因说明

Selenium默认启动的是隔离态的干净Chrome实例,不会加载本地常规Chrome中存储的用户配置、设备注册凭据、Azure AD身份缓存,因此Azure条件访问策略无法识别设备的已注册合规状态,仅在自动化启动浏览器时触发报错,本地正常使用Chrome不受影响。

报错详情

登录错误代码:53000
失败原因:Device is not in required device state: {state}。Conditional Access policy要求使用合规设备,当前设备不合规,用户必须通过Intune等经批准的MDM提供商注册设备。
附加详情:管理员可能配置了条件访问策略,仅允许合规设备访问组织资源。设备需加入本地Active Directory或Azure Active Directory才可满足合规要求。

Device state: Unregistered报错截图

可落地解决方案

  • 加载本地Chrome用户配置文件启动
    先关闭所有本地打开的Chrome窗口,避免配置文件被占用,再在Selenium的Chrome启动参数中指定加载本地默认配置,Python示例代码如下:
    from selenium import webdriver
    from selenium.webdriver.chrome.options import Options
    
    chrome_options = Options()
    # Windows路径示例,替换为你实际的用户配置路径
    chrome_options.add_argument(r"user-data-dir=C:\Users\你的用户名\AppData\Local\Google\Chrome\User Data")
    chrome_options.add_argument("profile-directory=Default")
    driver = webdriver.Chrome(options=chrome_options)
    
    不同操作系统的Chrome默认配置路径:
    • Mac:/Users/你的用户名/Library/Application Support/Google/Chrome
    • Linux:/home/你的用户名/.config/google-chrome
  • 调整Azure条件访问策略(需管理员权限)
    联系Azure AD管理员,将自动化使用的账号、运行自动化的固定IP添加到对应条件访问策略的排除列表中,跳过合规设备校验要求。
  • 改用Azure官方接口执行操作
    放弃Selenium模拟UI操作的方案,直接使用Azure PowerShell、Azure CLI或者REST API执行VM启用复制操作,完全规避浏览器端的条件访问校验,自动化执行效率和稳定性更高。

内容的提问来源于stack exchange,提问作者Pintu Gorai

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.03 10:36:03