You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用PowerShell处理Azure Cube时遭遇认证失败连接问题

解决Invoke-ProcessASDatabase的认证失败问题

我看你遇到的问题是Invoke-ProcessASDatabase这个cmdlet没法直接用Azure RunAs连接的证书凭据来认证Azure Analysis Services(AAS)。这个命令属于SqlServer模块,它对Azure AD身份认证的支持需要特定配置,下面给你一步步解决方案:

1. 先确保服务主体拥有AAS的访问权限

首先得给Azure RunAs服务主体(或者你尝试使用的Samcred对应的服务主体)分配AAS服务器的管理员权限:

  • 登录Azure门户,找到你的Analysis Services服务器
  • 进入安全性 > 服务器管理员
  • 添加服务主体的应用ID(格式可以是appid@tenantid或者直接用应用ID)到管理员列表,保存更改

2. 修正PowerShell代码中的凭据处理

你的代码里$SPCredential被注释掉了,而且即使启用,Azure RunAs的证书凭据是给Azure资源管理器用的,没法直接被AAS的cmdlet识别。这里有两种可行的修正方案:

方案一:用服务主体的客户端密钥创建PSCredential

如果你的服务主体有客户端密钥(不是证书),可以把它存储在自动化账户的凭据资产中,然后这样调用:

# 获取存储的服务主体凭据(用户名是服务主体ApplicationId,密码是客户端密钥)
$spCredential = Get-AutomationPSCredential -Name "Samcred"

# 调用时指定*ActiveDirectoryPassword*认证方式
Invoke-ProcessASDatabase -DatabaseName $DatabaseName -Server $AnalysisServerName -RefreshType "Full" -Credential $spCredential -Authentication ActiveDirectoryPassword

方案二:用Azure RunAs证书获取AAS访问令牌

如果坚持用Azure RunAs的证书认证,可以先获取AAS的访问令牌,再转换成cmdlet能接受的凭据:

# 获取AAS服务的访问令牌
$token = Get-AzAccessToken -ResourceUrl "https://*.asazure.windows.net"
# 创建PSCredential对象(用户名可以是任意占位值,密码是令牌内容)
$tokenCredential = New-Object System.Management.Automation.PSCredential("dummyUser", (ConvertTo-SecureString $token.Token -AsPlainText -Force))

# 用令牌凭据调用处理命令
Invoke-ProcessASDatabase -DatabaseName $DatabaseName -Server $AnalysisServerName -RefreshType "Full" -Credential $tokenCredential -Authentication ActiveDirectoryPassword

3. 确保使用最新版SqlServer模块

旧版本的SqlServer模块对Azure AD认证支持有限,建议在自动化账户里更新到最新版:

  • 登录Azure自动化账户
  • 进入共享资源 > 模块
  • 搜索SqlServer,如果版本较低,点击更新到最新版本

修正后的完整代码示例(方案二)

# Connect to Azure using RunAs Connection
$connectionName = "AzureRunAsConnection"
try {
    $servicePrincipalConnection = Get-AutomationConnection -Name $connectionName
    "Logging in to Azure..."
    Connect-AzAccount `
        -ServicePrincipal `
        -TenantId $servicePrincipalConnection.TenantId `
        -ApplicationId $servicePrincipalConnection.ApplicationId `
        -CertificateThumbprint $servicePrincipalConnection.CertificateThumbprint
} catch {
    if (!$servicePrincipalConnection) {
        $ErrorMessage = "Connection $connectionName not found."
        throw $ErrorMessage
    } else{
        Write-Error -Message $_.Exception
        throw $_.Exception
    }
}

# Select the correct subscription
$SubscriptionId = $servicePrincipalConnection.SubscriptionId
Write-Output "Selecting subscription '$($SubscriptionId)'.."
Select-AzSubscription -SubscriptionID $SubscriptionId

# Get variable values
$DatabaseName = Get-AutomationVariable -Name 'DatabaseName'
$AnalysisServerName = Get-AutomationVariable -Name 'AnalysisServerName'

# Show info before processing
Write-Output "Processing $($DatabaseName) on $($AnalysisServerName)"

# Get AAS access token and create credential
$token = Get-AzAccessToken -ResourceUrl "https://*.asazure.windows.net"
$tokenCredential = New-Object System.Management.Automation.PSCredential("dummyUser", (ConvertTo-SecureString $token.Token -AsPlainText -Force))

# Process database with token-based authentication
Invoke-ProcessASDatabase -DatabaseName $DatabaseName -Server $AnalysisServerName -RefreshType "Full" -Credential $tokenCredential -Authentication ActiveDirectoryPassword

Write-Output "Done"

内容的提问来源于stack exchange,提问作者Darko Milic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:12:05