基于AAD v1应用注册的Office Add-In SSO:获取SharePoint术语库访问令牌咨询
Absolutely, you can get an access token for SharePoint while maintaining your SSO single sign-on functionality, and adjusting your Azure AD application registration is key to making this work. Here's how to approach it:
1. Update Your Azure AD App's Permissions
First, you need to add SharePoint-specific permissions to your registered Azure AD app. These permissions will let your add-in access the term store via SharePoint's APIs:
- Head to your app registration in the Azure AD portal, navigate to API Permissions
- Click Add a permission > Select SharePoint > Choose Delegated permissions (since this is user-centric SSO)
- Look for permissions like
TermStore.Read.AllorTermStore.ReadWrite.Alldepending on whether you need read-only or write access - Don't forget to grant admin consent for these permissions if required for your tenant
2. Adjust Your Access Token Request for SharePoint
When you originally fetched a token for Graph API, you targeted the Graph resource. Now, you'll need to request a token for your SharePoint tenant resource:
- If you're using Office.js's
getAccessTokenmethod, specify theresourceparameter as your SharePoint tenant root URL (e.g.,https://yourtenant.sharepoint.com) or a specific scope likehttps://yourtenant.sharepoint.com/TermStore.Read.All - This tells Azure AD to issue a token valid for SharePoint resources instead of Graph, while reusing the existing user SSO session so the user doesn't have to log in again
3. Use SharePoint's REST API to Retrieve the Term Store
Once you have the SharePoint access token, you can call SharePoint's REST API to access the term store. For example:
- To get the root term store:
GET https://your-site-url/_api/v2.1/termStore Headers: Authorization: Bearer <your-sharepoint-access-token> Accept: application/json - To fetch specific term sets:
GET https://your-site-url/_api/v2.1/termStore/sets Headers: Authorization: Bearer <your-sharepoint-access-token> Accept: application/json
4. Maintain SSO Continuity
The beauty here is that you won't break your existing SSO flow:
- Office handles the user's authentication session behind the scenes, so requesting a SharePoint token will reuse the same session established during your initial Graph API flow
- Users only need to sign in once, and your add-in can seamlessly switch between Graph and SharePoint tokens as needed
Key Notes
- Make sure the user has direct permissions to access the SharePoint term store (app permissions alone aren't enough—users need appropriate SharePoint permissions too)
- Verify your Azure AD app's redirect URIs and authentication settings are correctly configured for your Office Add-In
内容的提问来源于stack exchange,提问作者Nick

