You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Microsoft Graph API重置密码:客户端凭证流权限问题咨询

能否通过Client Credentials Grant Flow实现AAD用户密码重置?

Absolutely, you can use the Client Credentials Grant Flow to update a user's PasswordProfile via Microsoft Graph—but the Authorization_RequestDenied error you're seeing stems from incomplete or unconsented permissions. Let's break down what you need to fix this:

1. Required Application Permissions

To modify a user's password, your AAD app needs one of the following application-level permissions (not delegated permissions—since Client Credentials runs as the app itself, not a specific user):

  • User.ReadWrite.All: Allows the app to read and write all user properties, including password profiles
  • Directory.AccessAsUser.All: A broader permission that lets the app act as any user in the directory, including performing password updates

Critical Note:

These are high-privilege permissions—you must obtain admin consent for them. Simply adding the permission to your app registration isn't enough; a Global Administrator or Privileged Role Administrator has to explicitly grant consent through the Azure Portal.

2. Step-by-Step Permission Configuration

  • Navigate to the Azure Portal, find your App Registration, and go to the API Permissions section
  • Click Add Permission > Select Microsoft Graph
  • Choose Application Permissions, search for the permission you need (e.g., User.ReadWrite.All), select it, and click Add Permissions
  • Finally, click Grant Admin Consent for [Your Tenant Name]—wait until the permission status updates to "Granted"

3. API Call Guidelines

  • When requesting an access token via the Client Credentials flow, use the scope https://graph.microsoft.com/.default
  • Your PATCH request to /users/{userId} should include a properly formatted passwordProfile object. Example request body:
    {
      "passwordProfile": {
        "password": "YourSecurePassword123!",
        "forceChangePasswordNextSignIn": false
      }
    }
    

4. Common Mistakes to Avoid

  • Don't use delegated permissions: The Client Credentials flow operates at the application level, so delegated scopes (which rely on a user context) won't work here
  • Wait for permission propagation: After granting admin consent, it can take 5-10 minutes for Azure AD to fully apply the permission changes
  • Verify token scopes: Check the access token you receive using a tool like jwt.ms—ensure it includes the required permission (e.g., User.ReadWrite.All) in the roles claim

内容的提问来源于stack exchange,提问作者Adoyt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:02:03