You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure AD中为无所有者的注册应用添加新所有者

解决Azure AD无所有者注册应用的管理问题

别担心,这种情况完全可以通过PowerShell(推荐用Microsoft Graph PowerShell模块,或者AzureAD模块)来添加新所有者,我给你一步步讲清楚:

第一步:先试试Portal里的简单方法(可能不用命令)

有时候因为应用没有所有者,默认在App Registrations的「My applications」筛选器里看不到,你可以先这么操作:

  • 打开Azure Portal,进入Azure Active Directory → App Registrations
  • 点击页面顶部的筛选器,把「My applications」切换成「All applications」
  • 搜索你的应用名称或App ID,看看能不能找到。如果能找到,直接进入应用详情页,切换到Owners选项卡,点击「Add owners」选择内部用户添加即可。

如果上面的方法找不到应用,再用下面的PowerShell方案。

第二步:用Microsoft Graph PowerShell添加所有者(推荐,因为AzureAD模块逐步淘汰)

1. 准备工作:安装并连接模块

首先打开PowerShell(以管理员身份运行),安装Microsoft Graph模块:

Install-Module Microsoft.Graph -Scope CurrentUser -Force

然后连接到Graph,需要申请足够的权限(Application.ReadWrite.All和Directory.Read.All):

Connect-MgGraph -Scopes "Application.ReadWrite.All", "Directory.Read.All"

按照提示登录你的管理员账号。

2. 找到目标应用的信息

因为你能在Enterprise Applications里看到应用,先通过服务主体定位它:

# 替换成你的应用显示名称
Get-MgServicePrincipal -Filter "DisplayName eq '你的应用名称'"

或者用应用的App ID(从Enterprise Applications的应用详情里能找到):

# 替换成你的应用App ID
Get-MgServicePrincipal -Filter "AppId eq 'xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx'"

从返回结果里复制AppId字段,然后用它找到对应的应用注册:

Get-MgApplication -Filter "AppId eq '刚才复制的AppId'"

复制返回结果里的Id(这是应用注册的Object ID)。

3. 添加新所有者

先获取要添加为所有者的用户信息:

# 替换成目标用户的UPN
$targetUser = Get-MgUser -Filter "UserPrincipalName eq 'user@yourdomain.com'"

然后执行添加命令:

# 替换成刚才复制的应用注册Object ID
New-MgApplicationOwnerByRef -ApplicationId "应用注册Object ID" -BodyParameter @{ "@odata.id" = "https://graph.microsoft.com/v1.0/users/$($targetUser.Id)" }

第三步:用AzureAD模块的备选方案(如果不想用Graph)

如果你习惯用旧的AzureAD模块,也可以这么操作:

1. 安装并连接模块

Install-Module AzureAD -Scope CurrentUser -Force
Connect-AzureAD

2. 定位应用并获取ID

# 找服务主体
Get-AzureADServicePrincipal -Filter "DisplayName eq '你的应用名称'"
# 用App ID找应用注册
$targetApp = Get-AzureADApplication -Filter "AppId eq '你的应用App ID'"

3. 添加所有者

$targetUser = Get-AzureADUser -Filter "UserPrincipalName eq 'user@yourdomain.com'"
Add-AzureADApplicationOwner -ObjectId $targetApp.ObjectId -RefObjectId $targetUser.ObjectId

验证结果

添加完成后,回到Azure Portal的App Registrations(切换到All applications筛选器),就能看到这个应用了,进入详情页的Owners选项卡也能看到新添加的所有者,之后就能正常管理应用(比如添加密钥)了。

内容的提问来源于stack exchange,提问作者synic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:53:27