You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Java中获取Azure AD应用客户端密钥过期日期

我来帮你搞定这个问题!要通过Azure SDK for Java获取Azure AD应用注册的凭据过期日期,你需要用到Microsoft Graph SDK for Java——因为Azure AD的应用凭据信息是通过Graph API来管理的,而非Azure Management SDK(后者更多用于管理VM、存储这类Azure资源)。下面是完整的实现步骤:

步骤1:添加必要的依赖

首先在你的pom.xml里引入Microsoft Graph SDK和Azure身份认证相关的依赖(用最新稳定版即可):

<dependencies>
    <!-- Microsoft Graph SDK 核心依赖 -->
    <dependency>
        <groupId>com.microsoft.graph</groupId>
        <artifactId>microsoft-graph</artifactId>
        <version>6.7.0</version>
    </dependency>
    <!-- Azure Identity 用于获取Graph API的访问令牌 -->
    <dependency>
        <groupId>com.azure</groupId>
        <artifactId>azure-identity</artifactId>
        <version>1.12.0</version>
    </dependency>
</dependencies>
步骤2:配置认证权限

你需要确保用于认证的主体(服务主体或你的个人账户)拥有Application.Read.All权限:

  • 如果用服务主体:在Azure AD里给该服务主体添加「Microsoft Graph」的应用权限,选择Application.Read.All,然后点击「授予管理员同意」。
  • 如果用个人账户:添加「Microsoft Graph」的委派权限,同样选择Application.Read.All,并确保账户有足够的租户权限。
步骤3:编写Java代码获取凭据过期日期

下面是完整的代码示例,这里用服务主体认证(ClientSecretCredential),适合后台服务场景;如果是桌面应用,可以换成InteractiveBrowserCredential这类交互式认证方式:

import com.azure.identity.ClientSecretCredential;
import com.azure.identity.ClientSecretCredentialBuilder;
import com.microsoft.graph.models.Application;
import com.microsoft.graph.models.PasswordCredential;
import com.microsoft.graph.requests.GraphServiceClient;
import okhttp3.Request;

import java.util.List;

public class AppCredentialExpiryChecker {
    public static void main(String[] args) {
        // 替换成你的租户和认证信息
        String tenantId = "你的Azure AD租户ID";
        String authClientId = "用于认证的服务主体Client ID";
        String authClientSecret = "用于认证的服务主体密钥";
        String targetAppClientId = "你要查询的应用的Client ID";

        // 创建服务主体认证凭据
        ClientSecretCredential credential = new ClientSecretCredentialBuilder()
                .tenantId(tenantId)
                .clientId(authClientId)
                .clientSecret(authClientSecret)
                .build();

        // 初始化Graph Service客户端
        GraphServiceClient<Request> graphClient = GraphServiceClient
                .builder()
                .authenticationProvider(request -> {
                    // 获取Graph API的访问令牌
                    String accessToken = credential.getToken("https://graph.microsoft.com/.default").block().getToken();
                    request.addHeader("Authorization", "Bearer " + accessToken);
                    return request;
                })
                .buildClient();

        try {
            // 通过Client ID查询目标应用(Azure AD中AppID/ClientID是唯一的)
            Application targetApp = graphClient.applications()
                    .filter("appId eq '" + targetAppClientId + "'")
                    .buildRequest()
                    .get()
                    .getCurrentPage()
                    .get(0);

            System.out.println("=== 应用【" + targetApp.displayName + "】的凭据信息 ===");

            // 处理密码凭据(也就是你说的客户端密钥)
            List<PasswordCredential> passwordCreds = targetApp.passwordCredentials;
            if (passwordCreds != null && !passwordCreds.isEmpty()) {
                System.out.println("\n--- 密码凭据(客户端密钥)---");
                for (PasswordCredential cred : passwordCreds) {
                    System.out.println("凭据名称: " + cred.displayName);
                    System.out.println("过期日期: " + cred.endDateTime);
                    System.out.println("创建日期: " + cred.startDateTime);
                    System.out.println("------------------------");
                }
            } else {
                System.out.println("\n未找到密码凭据");
            }

            // 处理证书凭据(如果你的应用用了证书认证)
            List<com.microsoft.graph.models.KeyCredential> keyCreds = targetApp.keyCredentials;
            if (keyCreds != null && !keyCreds.isEmpty()) {
                System.out.println("\n--- 证书凭据 ---");
                for (com.microsoft.graph.models.KeyCredential cred : keyCreds) {
                    System.out.println("凭据名称: " + cred.displayName);
                    System.out.println("过期日期: " + cred.endDateTime);
                    System.out.println("创建日期: " + cred.startDateTime);
                    System.out.println("------------------------");
                }
            } else {
                System.out.println("\n未找到证书凭据");
            }

        } catch (Exception e) {
            e.printStackTrace();
            System.err.println("获取凭据信息失败: " + e.getMessage());
        }
    }
}
关键注意事项
  1. Graph API的必要性:Azure Management SDK无法直接读取AD应用的凭据细节,必须通过Microsoft Graph API来获取。
  2. 权限验证:如果运行时报403错误,一定要检查权限是否正确配置,尤其是应用权限需要管理员手动同意。
  3. Client ID唯一性:Azure AD中每个应用的appId(即Client ID)是全局唯一的,所以用filter("appId eq 'xxx'")可以精准定位目标应用。

内容的提问来源于stack exchange,提问作者rupa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 06:55:44