如何通过应用用户使用PowerShell连接Microsoft CRM 365 Online?
Connecting to Dynamics 365 Online with Application User via PowerShell's
Get-CrmConnection Got it, let's walk through exactly how to set this up—you're right that using an application user (service principal) requires a specific connection string format, different from the username/password flow you've been using.
Prerequisites First
Before diving into the connection string, make sure you have these pieces in place:
- An Azure AD application registered (this is the same one you use for the Web API)
- The application has been created as an application user in your Dynamics 365 org (under Settings > Security > Users)
- The application user is assigned a security role with the necessary permissions (e.g., System Administrator, or a custom role tailored to your needs)
Correct Connection String Format
For application user authentication (client secret flow), your connection string needs to use AuthType=ClientSecret and include these critical parameters:
AuthType=ClientSecret;ClientId=YOUR_APP_CLIENT_ID;ClientSecret=YOUR_APP_CLIENT_SECRET;Url=https://your-org.crm.dynamics.com;TenantId=YOUR_AZURE_AD_TENANT_ID
Let's break down each parameter:
ClientId: The Application (Client) ID of your Azure AD app (found in Azure Portal > App Registrations > Your App > Overview)ClientSecret: A client secret generated for your Azure AD app (created under Certificates & Secrets > Client Secrets)Url: The base URL of your Dynamics 365 organization (e.g.,https://contoso.crm.dynamics.com)TenantId: Your Azure AD tenant ID (can be the tenant GUID or your onmicrosoft.com domain, likecontoso.onmicrosoft.com)
PowerShell Code Example
Here's how to implement this in a script (replace placeholders with your actual values):
# Define your authentication parameters $clientId = "12345678-1234-1234-1234-1234567890ab" $clientSecret = "your-client-secret-here" $crmOrgUrl = "https://your-org-name.crm.dynamics.com" $tenantId = "contoso.onmicrosoft.com" # Build the connection string $connectionString = "AuthType=ClientSecret;ClientId=$clientId;ClientSecret=$clientSecret;Url=$crmOrgUrl;TenantId=$tenantId" # Establish the CRM connection try { $crmConnection = Get-CrmConnection -ConnectionString $connectionString Write-Host "Successfully connected to Dynamics 365!" -ForegroundColor Green # Test the connection by fetching org details $orgDetails = Get-CrmOrganization -Connection $crmConnection Write-Host "Connected to organization: $($orgDetails.FriendlyName)" } catch { Write-Host "Connection failed: $_" -ForegroundColor Red }
Key Notes to Avoid Issues
- Don't hardcode secrets: For production scripts, store the client secret in a secure location like Azure Key Vault and retrieve it dynamically, instead of embedding it directly.
- Certificate-based auth (optional): If you prefer using a certificate instead of a client secret, change the
AuthTypetoCertificateand replaceClientSecretwithCertificateThumbprint=YOUR_CERT_THUMBPRINT. - Permission checks: If you get "access denied" errors, double-check that the application user in D365 has the right security roles assigned—this is a common gotcha.
内容的提问来源于stack exchange,提问作者Dejan Dular
相关产品推荐
相关产品推荐

