You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Azure Graph或REST API获取AAD用户可注册应用权限配置

实现方案

你要获取的「Restrict member users default permissions → Users can register application」配置,可通过Microsoft Graph API的授权策略接口实现,无需交互式登录,使用服务主体的客户端凭据流即可完成认证,适配.NET Framework环境。

前提准备

  • 在Azure Portal中注册企业应用,为其分配Application类型的Policy.Read.All权限,需由全局管理员完成权限授予操作
  • 保存该应用的客户端ID、客户端密钥、所属Azure AD租户ID三个参数

核心逻辑

该配置对应Graph接口返回值中defaultUserRolePermissions.allowedToCreateApps布尔字段:

  • 值为true:允许普通成员用户注册应用
  • 值为false:限制普通成员用户注册应用

.NET Framework 代码示例

首先安装必要的NuGet包:

  • Microsoft.Identity.Client(用于获取访问令牌)
  • Newtonsoft.Json(用于解析返回结果)

示例代码如下:

using System;
using System.Net.Http;
using System.Net.Http.Headers;
using Microsoft.Identity.Client;
using Newtonsoft.Json.Linq;

class Program
{
    // 替换为你自己的应用参数
    private const string TenantId = "你的Azure AD租户ID";
    private const string ClientId = "注册应用的客户端ID";
    private const string ClientSecret = "注册应用的客户端密钥";
    private const string GraphApiUrl = "https://graph.microsoft.com/v1.0/policies/authorizationPolicy";

    static void Main(string[] args)
    {
        // 客户端凭据流获取访问令牌
        IConfidentialClientApplication app = ConfidentialClientApplicationBuilder
            .Create(ClientId)
            .WithClientSecret(ClientSecret)
            .WithAuthority($"https://login.microsoftonline.com/{TenantId}")
            .Build();

        string[] scopes = new string[] { "https://graph.microsoft.com/.default" };
        var result = app.AcquireTokenForClient(scopes).ExecuteAsync().Result;

        // 调用Graph接口获取配置
        using (HttpClient httpClient = new HttpClient())
        {
            httpClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", result.AccessToken);
            var response = httpClient.GetAsync(GraphApiUrl).Result;
            if (response.IsSuccessStatusCode)
            {
                string content = response.Content.ReadAsStringAsync().Result;
                JObject policyData = JObject.Parse(content);
                bool allowRegisterApp = (bool)policyData["defaultUserRolePermissions"]["allowedToCreateApps"];
                Console.WriteLine($"用户可注册应用配置值:{allowRegisterApp}");
            }
            else
            {
                Console.WriteLine($"接口调用失败,状态码:{response.StatusCode}");
            }
        }
    }
}

内容的提问来源于stack exchange,提问作者Kleber Bernardo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.07 05:39:00