如何通过Postman获取Azure AD实例中的用户列表?
Hey there! I’ve worked with Azure AD and Postman quite a bit, so let me break down exactly how to fetch your tenant’s user list step by step.
Prerequisites (Don’t skip this!)
First, you need to set up an app registration in Azure Portal—this is how Postman will authenticate with Azure AD:
- Log into the Azure Portal, navigate to Azure Active Directory → App registrations → New registration.
- Give your app a name, set the account type to Accounts in this organizational directory only (if you only need users from your own tenant).
- After registering, jot down the Application (client) ID and Directory (tenant) ID—you’ll need these later.
- Next, configure API permissions:
- Go back to your app registration → API permissions → Add a permission → Select Microsoft Graph.
- Choose Application permissions (great for background bulk pulls without user login), then search for and select the
User.Read.Allpermission. - Finally, click Grant admin consent for [your tenant name]—you’ll need admin rights to do this, otherwise the API will throw permission errors.
Step 1: Get an Access Token (Postman Request)
You need a valid access token to call the Microsoft Graph API. We’ll use the client credentials flow here:
- Method:
POST - URL:
https://login.microsoftonline.com/{your-tenant-id}/oauth2/v2.0/token(replace{your-tenant-id}with the ID you noted earlier) - Body: Select the
x-www-form-urlencodedformat, then add these key-value pairs:grant_type:client_credentialsclient_id: Your app’s Application (client) IDclient_secret: Go to your app registration → Certificates & secrets → Client secrets → New client secret. Generate one, copy it immediately (it only shows once!), and paste it here.scope:https://graph.microsoft.com/.default
- Send the request, and you’ll get a JSON response with an
access_token—copy this token, it’s your ticket to the next step.
Step 2: Fetch the User List via Microsoft Graph API
Now that you have your token, call the Graph API to get users:
- Method:
GET - URL:
https://graph.microsoft.com/v1.0/users- Want to filter or limit results? Add query parameters like:
?$select=id,displayName,userPrincipalNameto only return specific fields?$top=100to control the number of users per page (default is 100; you’ll need to handle pagination if you have more users)
- Want to filter or limit results? Add query parameters like:
- Headers:
Authorization:Bearer {your-access-token}(replace{your-access-token}with the token from Step 1)Content-Type:application/json
- Hit send, and you’ll get a JSON response with your tenant’s user list!
Quick Notes
- Double-check that the
User.Read.Allpermission was granted admin consent—if not, you’ll get a403 Forbiddenerror. - If you have more than 100 users, look for the
@odata.nextLinkin the response. Use that URL for your next request to get the next page of users. - For better security, consider using a certificate instead of a client secret for authentication—client secrets are easier to leak!
内容的提问来源于stack exchange,提问作者MukkuP
相关产品推荐
相关产品推荐

