You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过应用用户使用PowerShell连接Microsoft CRM 365 Online?

Connecting to Dynamics 365 Online with Application User via PowerShell's Get-CrmConnection

Got it, let's walk through exactly how to set this up—you're right that using an application user (service principal) requires a specific connection string format, different from the username/password flow you've been using.

Prerequisites First

Before diving into the connection string, make sure you have these pieces in place:

  • An Azure AD application registered (this is the same one you use for the Web API)
  • The application has been created as an application user in your Dynamics 365 org (under Settings > Security > Users)
  • The application user is assigned a security role with the necessary permissions (e.g., System Administrator, or a custom role tailored to your needs)

Correct Connection String Format

For application user authentication (client secret flow), your connection string needs to use AuthType=ClientSecret and include these critical parameters:

AuthType=ClientSecret;ClientId=YOUR_APP_CLIENT_ID;ClientSecret=YOUR_APP_CLIENT_SECRET;Url=https://your-org.crm.dynamics.com;TenantId=YOUR_AZURE_AD_TENANT_ID

Let's break down each parameter:

  • ClientId: The Application (Client) ID of your Azure AD app (found in Azure Portal > App Registrations > Your App > Overview)
  • ClientSecret: A client secret generated for your Azure AD app (created under Certificates & Secrets > Client Secrets)
  • Url: The base URL of your Dynamics 365 organization (e.g., https://contoso.crm.dynamics.com)
  • TenantId: Your Azure AD tenant ID (can be the tenant GUID or your onmicrosoft.com domain, like contoso.onmicrosoft.com)

PowerShell Code Example

Here's how to implement this in a script (replace placeholders with your actual values):

# Define your authentication parameters
$clientId = "12345678-1234-1234-1234-1234567890ab"
$clientSecret = "your-client-secret-here"
$crmOrgUrl = "https://your-org-name.crm.dynamics.com"
$tenantId = "contoso.onmicrosoft.com"

# Build the connection string
$connectionString = "AuthType=ClientSecret;ClientId=$clientId;ClientSecret=$clientSecret;Url=$crmOrgUrl;TenantId=$tenantId"

# Establish the CRM connection
try {
    $crmConnection = Get-CrmConnection -ConnectionString $connectionString
    Write-Host "Successfully connected to Dynamics 365!" -ForegroundColor Green

    # Test the connection by fetching org details
    $orgDetails = Get-CrmOrganization -Connection $crmConnection
    Write-Host "Connected to organization: $($orgDetails.FriendlyName)"
}
catch {
    Write-Host "Connection failed: $_" -ForegroundColor Red
}

Key Notes to Avoid Issues

  • Don't hardcode secrets: For production scripts, store the client secret in a secure location like Azure Key Vault and retrieve it dynamically, instead of embedding it directly.
  • Certificate-based auth (optional): If you prefer using a certificate instead of a client secret, change the AuthType to Certificate and replace ClientSecret with CertificateThumbprint=YOUR_CERT_THUMBPRINT.
  • Permission checks: If you get "access denied" errors, double-check that the application user in D365 has the right security roles assigned—this is a common gotcha.

内容的提问来源于stack exchange,提问作者Dejan Dular

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 02:24:18