调用Microsoft Graph获用户特殊属性时遇System.UnauthorizedAccessException
Hey there, let's break down why you're hitting that System.UnauthorizedAccessException when fetching skills, aboutMe, or responsibilities—while basic attributes like surname and mail work just fine. The root issue here is almost always incorrect permission scopes for the Microsoft Graph API.
Why /.default isn't working for you
The https://graph.microsoft.com/.default scope is a "static" scope that includes all permissions you've configured for your app in Azure AD. But if you haven't explicitly added the right permissions to access those richer profile attributes, even using .default won't grant you access. Basic fields like mail or surname are covered by minimal permissions (like User.ReadBasic.All), but fields like skills need more specific scopes.
The correct scopes to use
Depending on whether you're accessing the current user's data or another user's data, you'll need different scopes:
Accessing the currently signed-in user's skills/aboutMe:
Use the delegated scopehttps://graph.microsoft.com/User.Read. This scope lets apps read the full profile of the user who's signed in, including those richer attributes.Accessing another user's skills/aboutMe:
You'll need the delegated scopehttps://graph.microsoft.com/User.Read.All(for user context) or the application scopehttps://graph.microsoft.com/User.Read.All(for app-only context, no signed-in user).Important: If you're using the application-level
User.Read.Allpermission, you must go to your Azure AD app registration, add this permission, and click Grant admin consent for your tenant—otherwise, the token won't include the necessary permissions.
Step-by-step fix
- Head to your Azure AD App Registration portal, navigate to your app's API Permissions section.
- Remove any unnecessary permissions, then add the correct Microsoft Graph permission (either
User.ReadorUser.Read.All, depending on your use case). - For application permissions, make sure to grant admin consent.
- When fetching your token with ADAL4J, specify the exact scope instead of
.default—e.g., useUser.Read.Allas the scope value. - Test the API call again with the new token; you should now be able to retrieve
skills,aboutMe, andresponsibilitieswithout authorization errors.
内容的提问来源于stack exchange,提问作者Udo Schiefer

