如何在Azure AD中为无所有者的注册应用添加新所有者
解决Azure AD无所有者注册应用的管理问题
别担心,这种情况完全可以通过PowerShell(推荐用Microsoft Graph PowerShell模块,或者AzureAD模块)来添加新所有者,我给你一步步讲清楚:
第一步:先试试Portal里的简单方法(可能不用命令)
有时候因为应用没有所有者,默认在App Registrations的「My applications」筛选器里看不到,你可以先这么操作:
- 打开Azure Portal,进入Azure Active Directory → App Registrations
- 点击页面顶部的筛选器,把「My applications」切换成「All applications」
- 搜索你的应用名称或App ID,看看能不能找到。如果能找到,直接进入应用详情页,切换到Owners选项卡,点击「Add owners」选择内部用户添加即可。
如果上面的方法找不到应用,再用下面的PowerShell方案。
第二步:用Microsoft Graph PowerShell添加所有者(推荐,因为AzureAD模块逐步淘汰)
1. 准备工作:安装并连接模块
首先打开PowerShell(以管理员身份运行),安装Microsoft Graph模块:
Install-Module Microsoft.Graph -Scope CurrentUser -Force
然后连接到Graph,需要申请足够的权限(Application.ReadWrite.All和Directory.Read.All):
Connect-MgGraph -Scopes "Application.ReadWrite.All", "Directory.Read.All"
按照提示登录你的管理员账号。
2. 找到目标应用的信息
因为你能在Enterprise Applications里看到应用,先通过服务主体定位它:
# 替换成你的应用显示名称 Get-MgServicePrincipal -Filter "DisplayName eq '你的应用名称'"
或者用应用的App ID(从Enterprise Applications的应用详情里能找到):
# 替换成你的应用App ID Get-MgServicePrincipal -Filter "AppId eq 'xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx'"
从返回结果里复制AppId字段,然后用它找到对应的应用注册:
Get-MgApplication -Filter "AppId eq '刚才复制的AppId'"
复制返回结果里的Id(这是应用注册的Object ID)。
3. 添加新所有者
先获取要添加为所有者的用户信息:
# 替换成目标用户的UPN $targetUser = Get-MgUser -Filter "UserPrincipalName eq 'user@yourdomain.com'"
然后执行添加命令:
# 替换成刚才复制的应用注册Object ID New-MgApplicationOwnerByRef -ApplicationId "应用注册Object ID" -BodyParameter @{ "@odata.id" = "https://graph.microsoft.com/v1.0/users/$($targetUser.Id)" }
第三步:用AzureAD模块的备选方案(如果不想用Graph)
如果你习惯用旧的AzureAD模块,也可以这么操作:
1. 安装并连接模块
Install-Module AzureAD -Scope CurrentUser -Force Connect-AzureAD
2. 定位应用并获取ID
# 找服务主体 Get-AzureADServicePrincipal -Filter "DisplayName eq '你的应用名称'" # 用App ID找应用注册 $targetApp = Get-AzureADApplication -Filter "AppId eq '你的应用App ID'"
3. 添加所有者
$targetUser = Get-AzureADUser -Filter "UserPrincipalName eq 'user@yourdomain.com'" Add-AzureADApplicationOwner -ObjectId $targetApp.ObjectId -RefObjectId $targetUser.ObjectId
验证结果
添加完成后,回到Azure Portal的App Registrations(切换到All applications筛选器),就能看到这个应用了,进入详情页的Owners选项卡也能看到新添加的所有者,之后就能正常管理应用(比如添加密钥)了。
内容的提问来源于stack exchange,提问作者synic
相关产品推荐
相关产品推荐

