You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用Microsoft Graph获用户特殊属性时遇System.UnauthorizedAccessException

Fixing Unauthorized Access for Microsoft Graph User Profile Attributes

Hey there, let's break down why you're hitting that System.UnauthorizedAccessException when fetching skills, aboutMe, or responsibilities—while basic attributes like surname and mail work just fine. The root issue here is almost always incorrect permission scopes for the Microsoft Graph API.

Why /.default isn't working for you

The https://graph.microsoft.com/.default scope is a "static" scope that includes all permissions you've configured for your app in Azure AD. But if you haven't explicitly added the right permissions to access those richer profile attributes, even using .default won't grant you access. Basic fields like mail or surname are covered by minimal permissions (like User.ReadBasic.All), but fields like skills need more specific scopes.

The correct scopes to use

Depending on whether you're accessing the current user's data or another user's data, you'll need different scopes:

  • Accessing the currently signed-in user's skills/aboutMe:
    Use the delegated scope https://graph.microsoft.com/User.Read. This scope lets apps read the full profile of the user who's signed in, including those richer attributes.

  • Accessing another user's skills/aboutMe:
    You'll need the delegated scope https://graph.microsoft.com/User.Read.All (for user context) or the application scope https://graph.microsoft.com/User.Read.All (for app-only context, no signed-in user).

    Important: If you're using the application-level User.Read.All permission, you must go to your Azure AD app registration, add this permission, and click Grant admin consent for your tenant—otherwise, the token won't include the necessary permissions.

Step-by-step fix

  1. Head to your Azure AD App Registration portal, navigate to your app's API Permissions section.
  2. Remove any unnecessary permissions, then add the correct Microsoft Graph permission (either User.Read or User.Read.All, depending on your use case).
  3. For application permissions, make sure to grant admin consent.
  4. When fetching your token with ADAL4J, specify the exact scope instead of .default—e.g., use User.Read.All as the scope value.
  5. Test the API call again with the new token; you should now be able to retrieve skills, aboutMe, and responsibilities without authorization errors.

内容的提问来源于stack exchange,提问作者Udo Schiefer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:27:05