You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Microsoft Graph API邀请Azure AD用户失败,返回Unauthorized错误

Hey there, let's tackle this "Unauthorized" error you're getting when trying to invite external users via Microsoft Graph API. I've gone through your code and there are a few key areas we need to check—let's break them down step by step:

1. Fix the Graph API Version First

Wait, I noticed you're using v1.6/invitations in your request URL, but Microsoft Graph API doesn't have a v1.6 version. The valid stable version is v1.0, so you should update that endpoint to:

"v1.0/invitations"

Using an invalid version might cause unexpected auth issues or outright request failures, so this is a quick first fix.

2. Verify Your App Registration Has the Correct Permissions

To invite external users via app-only authentication (which it looks like you're using with GetTokenForApplication()), your Azure AD app registration needs the right Microsoft Graph permissions:

  • Go to the Azure Portal → Azure AD → App Registrations → Your App → API Permissions
  • Add a permission → Select Microsoft Graph → Application Permissions
  • Search for and add User.Invite.All (this is the required permission for inviting external users via app context)
  • Critical step: Click Grant admin consent for [Your Tenant]—application permissions require admin approval to take effect

If you were using delegated permissions instead (for a user-facing app), you'd need User.Invite.All delegated permission, but since your code uses app-only token, stick with the application permission.

3. Ensure Your Access Token is Requested with the Right Scope

Check your AuthenticationHelper.GetTokenForApplication() method to make sure it's requesting the correct scope for app-only access. The scope should be:

https://graph.microsoft.com/.default

This tells Azure AD to issue a token with all the application permissions you've granted to the app. If you're using a different scope, the token won't include the User.Invite.All permission, leading to an Unauthorized response.

4. Validate the Token's Claims (Optional but Helpful)

If you're still stuck, use a tool like jwt.ms to decode your access token. Look for the roles claim in the token—you should see User.Invite.All listed there. If it's missing, that means the permission wasn't properly granted or the scope was wrong when requesting the token.

5. Double-Check App Registration Settings

Make sure your app registration is enabled in Azure AD:

  • Go to Azure AD → Enterprise Applications → Find your app → Ensure Enabled for users to sign-in? is set to Yes (though for app-only calls this might not be critical, but it's good to confirm)
  • Also, confirm that your app isn't restricted by any conditional access policies that might block Graph API calls

Here's your code snippet with the corrected API version for reference:

string accessToken = await AuthenticationHelper.GetTokenForApplication();
InvitationModel invite = new InvitationModel();
invite.invitedUserEmailAddress = user.Email;
invite.inviteRedirectUrl = ConfigurationManager.AppSettings["InviteRedirectUrl"];
invite.sendInvitationMessage = true;

using (HttpClient client = new HttpClient())
{
    client.BaseAddress = new Uri("https://graph.microsoft.com");
    client.DefaultRequestHeaders.Accept.Add(new MediaTypeWithQualityHeaderValue("application/json"));
    client.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", accessToken);
    
    // Corrected API version to v1.0
    HttpResponseMessage response = client.PostAsJsonAsync<InvitationModel>("v1.0/invitations", invite).Result;
    dynamic inviteResult = response.Content.ReadAsAsync<dynamic>().Result;
    
    if (inviteResult.status != "Error")
    {
        // Handle success
    }
}

Start with fixing the API version and verifying the permissions with admin consent—those are the most common culprits here. Let me know if you hit any snags after trying these steps!

内容的提问来源于stack exchange,提问作者user1500960

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:10:59