You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AzureAD PowerShell模块无法分配应用扩展值,求Graph API解决方案

Assigning Application Extension Values via Microsoft Graph API

Hey there! I get that the AzureAD PowerShell module falls short when it comes to assigning extension values to objects, even though you can create/remove extension properties with Get/New/Remove-AzureADApplicationExtensionProperty. Let's walk through exactly how to do this using the Graph API, building on the work you've already done with Fiddler and Postman.

Step 1: Get the full extension property name

First, you need the exact, formatted name of your extension property—this is crucial because Graph API uses a specific naming convention.

  • Using PowerShell: Run the command you already know to list your app's extension properties:

    Get-AzureADApplicationExtensionProperty -ObjectId "<your-application-object-id>"
    

    Look for the Name field in the output—it'll look like extension_<app-id-without-hyphens>_<your-property-name>.

  • Using Graph API: If you prefer, send a GET request to:

    GET https://graph.microsoft.com/v1.0/applications/{your-app-id}/extensionProperties
    

    The name field in the response is what you'll use in your update request.

Step 2: Secure a valid Bearer token

Since you've already tested this in Postman, you know the drill. You'll need an access token with the right permissions:

  • For updating user extension values: User.ReadWrite.All (or User.ReadWrite if targeting a single user you own)
  • For other objects (groups, apps, etc.): Use the corresponding write permission (e.g., Group.ReadWrite.All)

Step 3: Send a PATCH request to assign/update the extension value

Graph API uses the PATCH method to update object properties, including extension values. Here's how to structure the request:

Example: Update a user's extension property

  • Request URL:
    PATCH https://graph.microsoft.com/v1.0/users/{user-id-or-user-principal-name}
    
  • Headers:
    • Authorization: Bearer <your-access-token>
    • Content-Type: application/json
  • Request Body (replace the extension name and value with yours):
    {
      "extension_abc123def456ghi789jkl012mno345pqr678_EmployeeID": "EMP-7890"
    }
    

For other object types

Just swap the endpoint to match the object you're updating:

  • Groups: PATCH https://graph.microsoft.com/v1.0/groups/{group-id}
  • Applications: PATCH https://graph.microsoft.com/v1.0/applications/{app-id}

Step 4: Verify the change

To confirm the extension value was set correctly, send a GET request to fetch the object with your extension property included:

GET https://graph.microsoft.com/v1.0/users/{user-id}?$select=id,extension_abc123def456ghi789jkl012mno345pqr678_EmployeeID

Or back in PowerShell, you can check with:

Get-AzureADUser -ObjectId "<user-id>" | Select-Object -ExpandProperty ExtensionProperty

That's it! This should fill the gap left by the AzureAD PowerShell module for assigning those extension values.

内容的提问来源于stack exchange,提问作者Justin Dearing

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:10:02