You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过API方法获取微软自有API及对应权限列表?附Azure门户截图示例

获取微软自有API及对应权限的API途径与Azure门户参考

Great question! Yes, there's an official way to retrieve all Microsoft-owned APIs and their associated permissions via the Microsoft Graph API, plus you can cross-reference this with what you see in the Azure portal. Here's a breakdown:

1. 使用Microsoft Graph API获取数据

You can use the servicePrincipals endpoint in Microsoft Graph to fetch all Microsoft-published APIs, since each API corresponds to a service principal owned by Microsoft's official tenant.

核心请求示例

Filter service principals to only those owned by Microsoft by using the fixed Microsoft tenant ID f8cdef31-a31e-4b4a-93e4-5f571e91255a:

curl --request GET \
  --url 'https://graph.microsoft.com/v1.0/servicePrincipals?$filter=appOwnerOrganizationId eq ''f8cdef31-a31e-4b4a-93e4-5f571e91255a''' \
  --header 'Authorization: Bearer {your-access-token}'

关键权限字段解析

In the response, each service principal entry includes two key fields for permissions:

  • oauth2PermissionScopes: Contains all delegated permissions (permissions that act on behalf of a user). Each entry includes the permission's value (unique identifier), displayName (human-readable name), and description (what the permission allows).
  • appRoles: Contains all application permissions (permissions for background services/daemons that don't act on behalf of a user). These follow a similar structure to delegated permissions.

权限要求

To call this endpoint, your registered Azure AD application needs one of these permissions:

  • Directory.Read.All (delegated permission, works for user context)
  • Application.Read.All (application permission, ideal for service-to-service calls)

2. Azure门户参考(模拟截图场景)

If you want to visualize this data in the Azure portal (portal.azure.com), here's what the experience looks like:

  • Navigate to Azure Active Directory > Enterprise applications
  • Use the top filter to select All applications, then either search for a specific Microsoft API (e.g., "Microsoft Graph") or filter by Application type = Microsoft applications
  • Select the target API to open its details page, then switch to the Permissions tab
  • Here you'll see a categorized view of all delegated and application permissions, including details like whether admin consent is required, and a description of what each permission enables.

内容的提问来源于stack exchange,提问作者Ariel Larisma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 11:56:48