使用TFS+msdeploy部署Web应用遇ERROR_USER_UNAUTHORIZED授权错误求助
Let's break down your issue and walk through the fixes step by step:
Root Cause Analysis
Looking at your build log snippet, the critical issue is immediately clear:
msBuildArgs = /p:DeployOnBuild=true;PublishProfile=myProfile;AllowUntrustedCertificate=true;UserName=tfsadmin;Password=;Pass2=********
Your Password parameter is empty instead of showing as masked ********. This means the TFS build variable $(Password) isn't being passed correctly to MSBuild. When MSDeploy doesn't receive a valid password, it automatically falls back to using the account running the build agent (tfsadmin)—which is why you see that account in the IIS logs instead of your intended credentials. This mismatch triggers the ERROR_USER_UNAUTHORIZED error.
Step-by-Step Fixes
Verify Build Variable Configuration
- Navigate to your TFS build definition's Variables tab:
- Confirm you've created a variable named
Password(case-sensitive, no typos). - Check the Keep this value secret checkbox—this tells TFS to mask the value in logs and pass it securely. If this isn't enabled, the variable may fail to inject properly or appear empty.
- Double-check that the variable's value matches your target server's valid password.
- Confirm you've created a variable named
- Navigate to your TFS build definition's Variables tab:
Adjust MSBuild Argument Format
- Passwords often contain special characters (like
;,$, or spaces) that can break parameter parsing. Wrap thePasswordparameter in quotes to avoid this:/p:DeployOnBuild=true;PublishProfile=myProfile;AllowUntrustedCertificate=true;UserName=$(UserName);Password="$(Password)" - Open your
myProfile.pubxmlpublish profile file and remove any hardcoded<UserName>or<Password>nodes. These can override the parameters you pass via MSBuild, causing credential conflicts.
- Passwords often contain special characters (like
Validate Publish Profile Settings
- Ensure your publish profile (
myProfile.pubxml) is configured for remote deployment correctly:- Set
<PublishMethod>toMSDeploy - Set
<MSDeployServiceURL>to your target server's Web Management Service endpoint (e.g.,MySERVER:8172)
- Set
- Ensure your publish profile (
Enable Detailed Logging (For Troubleshooting)
- If you're still stuck, add the diagnostic logging flag to your MSBuild arguments to get deeper visibility into parameter processing:
/p:DeployOnBuild=true;PublishProfile=myProfile;AllowUntrustedCertificate=true;UserName=$(UserName);Password="$(Password)";/v:diag - This verbose logging will show exactly how MSBuild handles each parameter, helping you spot any remaining issues.
- If you're still stuck, add the diagnostic logging flag to your MSBuild arguments to get deeper visibility into parameter processing:
Final Notes
While you confirmed tfsadmin has admin rights on the target server, the core problem here is the missing password parameter. Fixing the variable injection should resolve the unauthorized error. Once the password is passed correctly, MSDeploy will use your specified credentials instead of falling back to the build agent account.
内容的提问来源于stack exchange,提问作者Omid Shariati

