You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何以编程方式在https://apps.dev.microsoft.com注册Azure AD v2融合应用?

Programmatically Register Azure AD v2 Converged Apps for apps.dev.microsoft.com

Hey there! Great question—yes, you absolutely can programmatically register Azure AD v2 converged apps that show up in the apps.dev.microsoft.com portal. The portal itself is built on top of the Microsoft Graph API, so that's the official, supported way to automate this process. Let's walk through how to do it:

Prerequisites

First, you'll need a few things in place:

  • A Microsoft 365 or Azure AD tenant (or even a personal Microsoft account, though some operations require tenant admin access).
  • A separate "service" application registered in Azure AD with permissions to create other apps. Specifically, you'll need one of these:
    • Application.ReadWrite.All: Lets you manage apps in your tenant (or across tenants if you have admin consent).
    • Directory.ReadWrite.All: A broader permission that includes app management—only use this if you need extra directory-level access.
  • An access token for your service app, obtained via OAuth 2.0 (client credentials flow for server-side automation, or authorization code flow if acting on behalf of a user).

Step 1: Get an Access Token

For server-side automation, use the client credentials flow to grab a token. Here's a quick curl example:

curl --request POST \
  --url https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/token \
  --header 'Content-Type: application/x-www-form-urlencoded' \
  --data 'client_id={your-service-app-client-id}&client_secret={your-service-app-client-secret}&scope=https://graph.microsoft.com/.default&grant_type=client_credentials'

Replace the placeholders with your actual values, then save the access_token from the response—you'll need it for the next step.

Step 2: Create the Converged Application

Use the Microsoft Graph POST /applications endpoint to create your v2 converged app. The critical property here is signInAudience, which you'll set to AzureADandPersonalMicrosoftAccount to enable both work/school accounts and personal Microsoft accounts.

Here's an example request for a web-based converged app:

curl --request POST \
  --url https://graph.microsoft.com/v1.0/applications \
  --header 'Authorization: Bearer {access-token}' \
  --header 'Content-Type: application/json' \
  --data '{
    "displayName": "My Converged Demo App",
    "signInAudience": "AzureADandPersonalMicrosoftAccount",
    "web": {
      "redirectUris": ["https://myapp.example.com/auth/callback"],
      "homePageUrl": "https://myapp.example.com"
    },
    "requiredResourceAccess": [
      {
        "resourceAppId": "00000003-0000-0000-c000-000000000000",
        "resourceAccess": [
          {
            "id": "e1fe6dd8-ba31-4d61-89e7-88639da4683d",
            "type": "Scope"
          }
        ]
      }
    ]
  }'

Key details to note:

  • signInAudience: This value marks the app as a v2 converged app.
  • web.redirectUris: The URIs where your app will receive authentication responses.
  • requiredResourceAccess: Optional, but this adds the basic User.Read permission for Microsoft Graph (the resourceAppId is Graph's official app ID, and the id corresponds to the User.Read scope).

Once you send this request, the app will be created instantly and will automatically appear in the apps.dev.microsoft.com portal when you log in with the same account/tenant.

Quick Additional Tips

  • To update the app later (add redirect URIs, tweak credentials, etc.), use the PATCH /applications/{app-id} endpoint.
  • To delete the app, use DELETE /applications/{app-id}.
  • For desktop/mobile apps, replace the web object with publicClient and set redirectUris to a platform-specific value (like msal{client-id}://auth for MSAL-based apps).

内容的提问来源于stack exchange,提问作者david rosko

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:48:26