如何通过API方法获取微软自有API及对应权限列表?附Azure门户截图示例
Great question! Yes, there's an official way to retrieve all Microsoft-owned APIs and their associated permissions via the Microsoft Graph API, plus you can cross-reference this with what you see in the Azure portal. Here's a breakdown:
1. 使用Microsoft Graph API获取数据
You can use the servicePrincipals endpoint in Microsoft Graph to fetch all Microsoft-published APIs, since each API corresponds to a service principal owned by Microsoft's official tenant.
核心请求示例
Filter service principals to only those owned by Microsoft by using the fixed Microsoft tenant ID f8cdef31-a31e-4b4a-93e4-5f571e91255a:
curl --request GET \ --url 'https://graph.microsoft.com/v1.0/servicePrincipals?$filter=appOwnerOrganizationId eq ''f8cdef31-a31e-4b4a-93e4-5f571e91255a''' \ --header 'Authorization: Bearer {your-access-token}'
关键权限字段解析
In the response, each service principal entry includes two key fields for permissions:
oauth2PermissionScopes: Contains all delegated permissions (permissions that act on behalf of a user). Each entry includes the permission'svalue(unique identifier),displayName(human-readable name), anddescription(what the permission allows).appRoles: Contains all application permissions (permissions for background services/daemons that don't act on behalf of a user). These follow a similar structure to delegated permissions.
权限要求
To call this endpoint, your registered Azure AD application needs one of these permissions:
Directory.Read.All(delegated permission, works for user context)Application.Read.All(application permission, ideal for service-to-service calls)
2. Azure门户参考(模拟截图场景)
If you want to visualize this data in the Azure portal (portal.azure.com), here's what the experience looks like:
- Navigate to Azure Active Directory > Enterprise applications
- Use the top filter to select All applications, then either search for a specific Microsoft API (e.g., "Microsoft Graph") or filter by Application type = Microsoft applications
- Select the target API to open its details page, then switch to the Permissions tab
- Here you'll see a categorized view of all delegated and application permissions, including details like whether admin consent is required, and a description of what each permission enables.
内容的提问来源于stack exchange,提问作者Ariel Larisma

