You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何查找Azure AD审计日志中DirectAccessGrantTypes等字段的详细说明

Azure AD 审计日志角色字段说明

两个字段的具体含义

  • DirectAccessGrantTypes:存储无需身份扮演场景下,允许直接使用当前应用角色的授权类型枚举值集合。你示例中出现的数值20对应客户端凭据流,也就是服务主体无需绑定用户上下文、直接以自身身份获取令牌访问资源的授权类型,标记该值的应用角色仅支持应用权限调用。
  • ImpersonationAccessGrantTypes:存储需要身份扮演场景下,允许使用当前应用角色的授权类型组合。每个元素包含两个枚举值:Impersonator为发起扮演的主体对应的授权类型,Impersonated为被扮演的主体对应的授权类型。你示例中出现的29对应委托权限场景下的用户扮演流程,说明对应的Read角色仅允许在指定的身份扮演授权流程中使用。

目前这两个字段属于Azure AD审计日志的半结构化内部字段,公开文档暂未覆盖完整的枚举值映射,你可以结合自身业务场景测试不同授权流触发的Update application日志,匹配得到自己业务覆盖场景下的枚举值对应关系。

你提供的日志样本参考

[
    {
        "EntitlementEncodingVersion": 2,
        "EntitlementId": "654a4f1f-1b7f-4354-a6d6-fcf7346af0ec",
        "IsDisabled": true,
        "Origin": 0,
        "Name": "Data Manager",
        "Description": "Manager for test app",
        "Definition": null,
        "ClaimValue": "DataManager",
        "ResourceScopeType": 0,
        "IsPrivate": false,
        "UserConsentDisplayName": null,
        "UserConsentDescription": null,
        "DirectAccessGrantTypes": [20],
        "ImpersonationAccessGrantTypes": [],
        "EntitlementCategory": 0,
        "DependentMicrosoftGraphPermissions": []
    },
    {
        "EntitlementEncodingVersion": 2,
        "EntitlementId": "3d03256d-cf0c-4553-b8af-98d7ebbee1f2",
        "IsDisabled": false,
        "Origin": 0,
        "Name": "Application Manager",
        "Description": "Admin for test app",
        "Definition": null,
        "ClaimValue": "ApplicationManager",
        "ResourceScopeType": 0,
        "IsPrivate": false,
        "UserConsentDisplayName": null,
        "UserConsentDescription": null,
        "DirectAccessGrantTypes": [20],
        "ImpersonationAccessGrantTypes": [],
        "EntitlementCategory": 0,
        "DependentMicrosoftGraphPermissions": []
    },
    {
        "EntitlementEncodingVersion": 2,
        "EntitlementId": "88d0d3e3-b661-4760-aea3-f4548db1ff96",
        "IsDisabled": false,
        "Origin": 0,
        "Name": "Read",
        "Description": "Allow users to add a admin consent",
        "Definition": null,
        "ClaimValue": "Read",
        "ResourceScopeType": 0,
        "IsPrivate": false,
        "UserConsentDisplayName": null,
        "UserConsentDescription": null,
        "DirectAccessGrantTypes": [],
        "ImpersonationAccessGrantTypes": [
            {
                "Impersonator": 29,
                "Impersonated": 20
            }
        ],
        "EntitlementCategory": 0,
        "DependentMicrosoftGraphPermissions": []
    }
]

内容的提问来源于stack exchange,提问作者FunkyMJ

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.04 22:12:01