如何通过Azure Graph或REST API获取AAD用户可注册应用权限配置
实现方案
你要获取的「Restrict member users default permissions → Users can register application」配置,可通过Microsoft Graph API的授权策略接口实现,无需交互式登录,使用服务主体的客户端凭据流即可完成认证,适配.NET Framework环境。
前提准备
- 在Azure Portal中注册企业应用,为其分配Application类型的
Policy.Read.All权限,需由全局管理员完成权限授予操作 - 保存该应用的客户端ID、客户端密钥、所属Azure AD租户ID三个参数
核心逻辑
该配置对应Graph接口返回值中defaultUserRolePermissions.allowedToCreateApps布尔字段:
- 值为
true:允许普通成员用户注册应用 - 值为
false:限制普通成员用户注册应用
.NET Framework 代码示例
首先安装必要的NuGet包:
Microsoft.Identity.Client(用于获取访问令牌)Newtonsoft.Json(用于解析返回结果)
示例代码如下:
using System; using System.Net.Http; using System.Net.Http.Headers; using Microsoft.Identity.Client; using Newtonsoft.Json.Linq; class Program { // 替换为你自己的应用参数 private const string TenantId = "你的Azure AD租户ID"; private const string ClientId = "注册应用的客户端ID"; private const string ClientSecret = "注册应用的客户端密钥"; private const string GraphApiUrl = "https://graph.microsoft.com/v1.0/policies/authorizationPolicy"; static void Main(string[] args) { // 客户端凭据流获取访问令牌 IConfidentialClientApplication app = ConfidentialClientApplicationBuilder .Create(ClientId) .WithClientSecret(ClientSecret) .WithAuthority($"https://login.microsoftonline.com/{TenantId}") .Build(); string[] scopes = new string[] { "https://graph.microsoft.com/.default" }; var result = app.AcquireTokenForClient(scopes).ExecuteAsync().Result; // 调用Graph接口获取配置 using (HttpClient httpClient = new HttpClient()) { httpClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", result.AccessToken); var response = httpClient.GetAsync(GraphApiUrl).Result; if (response.IsSuccessStatusCode) { string content = response.Content.ReadAsStringAsync().Result; JObject policyData = JObject.Parse(content); bool allowRegisterApp = (bool)policyData["defaultUserRolePermissions"]["allowedToCreateApps"]; Console.WriteLine($"用户可注册应用配置值:{allowRegisterApp}"); } else { Console.WriteLine($"接口调用失败,状态码:{response.StatusCode}"); } } } }
内容的提问来源于stack exchange,提问作者Kleber Bernardo
相关产品推荐
相关产品推荐

