如何以编程方式在https://apps.dev.microsoft.com注册Azure AD v2融合应用?
Hey there! Great question—yes, you absolutely can programmatically register Azure AD v2 converged apps that show up in the apps.dev.microsoft.com portal. The portal itself is built on top of the Microsoft Graph API, so that's the official, supported way to automate this process. Let's walk through how to do it:
Prerequisites
First, you'll need a few things in place:
- A Microsoft 365 or Azure AD tenant (or even a personal Microsoft account, though some operations require tenant admin access).
- A separate "service" application registered in Azure AD with permissions to create other apps. Specifically, you'll need one of these:
- Application.ReadWrite.All: Lets you manage apps in your tenant (or across tenants if you have admin consent).
- Directory.ReadWrite.All: A broader permission that includes app management—only use this if you need extra directory-level access.
- An access token for your service app, obtained via OAuth 2.0 (client credentials flow for server-side automation, or authorization code flow if acting on behalf of a user).
Step 1: Get an Access Token
For server-side automation, use the client credentials flow to grab a token. Here's a quick curl example:
curl --request POST \ --url https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/token \ --header 'Content-Type: application/x-www-form-urlencoded' \ --data 'client_id={your-service-app-client-id}&client_secret={your-service-app-client-secret}&scope=https://graph.microsoft.com/.default&grant_type=client_credentials'
Replace the placeholders with your actual values, then save the access_token from the response—you'll need it for the next step.
Step 2: Create the Converged Application
Use the Microsoft Graph POST /applications endpoint to create your v2 converged app. The critical property here is signInAudience, which you'll set to AzureADandPersonalMicrosoftAccount to enable both work/school accounts and personal Microsoft accounts.
Here's an example request for a web-based converged app:
curl --request POST \ --url https://graph.microsoft.com/v1.0/applications \ --header 'Authorization: Bearer {access-token}' \ --header 'Content-Type: application/json' \ --data '{ "displayName": "My Converged Demo App", "signInAudience": "AzureADandPersonalMicrosoftAccount", "web": { "redirectUris": ["https://myapp.example.com/auth/callback"], "homePageUrl": "https://myapp.example.com" }, "requiredResourceAccess": [ { "resourceAppId": "00000003-0000-0000-c000-000000000000", "resourceAccess": [ { "id": "e1fe6dd8-ba31-4d61-89e7-88639da4683d", "type": "Scope" } ] } ] }'
Key details to note:
signInAudience: This value marks the app as a v2 converged app.web.redirectUris: The URIs where your app will receive authentication responses.requiredResourceAccess: Optional, but this adds the basic User.Read permission for Microsoft Graph (theresourceAppIdis Graph's official app ID, and theidcorresponds to the User.Read scope).
Once you send this request, the app will be created instantly and will automatically appear in the apps.dev.microsoft.com portal when you log in with the same account/tenant.
Quick Additional Tips
- To update the app later (add redirect URIs, tweak credentials, etc.), use the
PATCH /applications/{app-id}endpoint. - To delete the app, use
DELETE /applications/{app-id}. - For desktop/mobile apps, replace the
webobject withpublicClientand setredirectUristo a platform-specific value (likemsal{client-id}://authfor MSAL-based apps).
内容的提问来源于stack exchange,提问作者david rosko

