MSAL鉴权的Angular应用调用MS Graph搜用户报displayName属性错误怎么办
问题解决方案
你遇到的报错是查询请求被路由到了非标准的旧版Profile服务导致的字段不匹配,具体问题及修复方法如下:
- 核心问题:调用微软Graph API对用户集合做
startswith前缀过滤时,除了需要传递ConsistencyLevel: eventual请求头,还必须同时附加$count=true查询参数,缺少该参数会触发服务端路由 fallback 到旧版Profile服务,该服务的字段定义和标准Graph用户接口不一致,因此找不到displayName属性。 - 次要优化点:直接拼接查询字符串容易出现URL编码问题,建议使用Angular内置的
HttpParams来构建查询参数,避免特殊字符转义异常。
修复后的代码示例:
import { HttpParams } from '@angular/common/http'; // 构建查询参数 const queryParams = new HttpParams() .set('$filter', "startswith(displayName,'Joh')") .set('$count', 'true'); this.http.get(`https://graph.microsoft.com/v1.0/users`, { headers: { ConsistencyLevel: 'eventual' }, params: queryParams }).subscribe((response: any) => { console.log(response); });
额外注意:你需要提前在Azure AD的应用注册页为当前应用授予
User.Read.All或Directory.Read.All权限,且权限需要完成管理员同意,否则接口会返回403权限不足错误。
内容的提问来源于stack exchange,提问作者Nico Schuck
相关产品推荐
相关产品推荐

