You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否通过单个应用程序化访问Azure、VSTS及Graph的Microsoft身份信息?

Single App Access for Microsoft Graph, Azure DevOps, and Azure Resources

Absolutely! You don’t need separate Azure AD applications to access Microsoft Graph, Azure DevOps (formerly VSTS), and Azure resources—you can handle all three with one registered app. Let’s break down how to set this up for your Node.js app using passport-azure-ad:

Step 1: Register a Single Azure AD App

Head to the Azure Portal, register a new Web app/API or Single-page application (match your Node.js app’s type), and configure your redirect URI (this is the callback URL where your app receives auth responses from Azure AD). You only need to set this up once for the app—no separate registrations needed for each service.

Step 2: Add Permissions for All Three Services

In your app’s API permissions blade in the Azure Portal, add the necessary permissions for each service:

  • Microsoft Graph: Add delegated permissions like User.Read (to fetch user profiles) or Directory.Read.All (if you need broader org data). For app-level access (no user context), use application permissions instead.
  • Azure DevOps: Search for the "Azure DevOps" API, then add delegated permissions like vso.build_read (to access build information) or vso.project_read (to view project details).
  • Azure Resource Manager: Search for "Azure Service Management", then add the user_impersonation delegated permission—this lets your app access Azure Resource Manager (ARM) APIs to pull service usage data.

Note: If you’re using permissions that require admin consent (like most application permissions or broad delegated scopes), you’ll need an Azure AD admin to grant consent for your organization.

Step 3: Configure passport-azure-ad for Multi-Service Access

Set up the OIDCStrategy in your Node.js app to request the right scopes during authentication. Your scope list should include permissions for all three services. For example:

const strategy = new OIDCStrategy({
  clientID: process.env.AZURE_AD_CLIENT_ID,
  clientSecret: process.env.AZURE_AD_CLIENT_SECRET,
  redirectUrl: process.env.AZURE_AD_REDIRECT_URI,
  identityMetadata: `https://login.microsoftonline.com/${process.env.TENANT_ID}/v2.0/.well-known/openid-configuration`,
  responseType: 'code id_token',
  responseMode: 'form_post',
  scope: 'openid profile User.Read vso.build_read https://management.azure.com/user_impersonation'
}, (iss, sub, profile, accessToken, refreshToken, done) => {
  // Handle user authentication here—store tokens for later use
  return done(null, { profile, accessToken, refreshToken });
});

Step 4: Use Tokens to Access Each Service

Once the user is authenticated, you’ll have an access token and refresh token. Here’s how to use them for each service:

  • Microsoft Graph: Use the access token directly to call Graph endpoints (e.g., https://graph.microsoft.com/v1.0/me). Include the token in the Authorization header as Bearer {accessToken}.
  • Azure DevOps: If your initial access token doesn’t include Azure DevOps scopes (or you need a token targeted specifically at Azure DevOps), use the refresh token to request a new access token for the Azure DevOps resource (https://app.vssps.visualstudio.com/). Then call endpoints like https://dev.azure.com/{your-org}/_apis/build/builds.
  • Azure Resource Manager: Similarly, use the refresh token to request an access token for the ARM resource (https://management.azure.com/), then call ARM APIs (e.g., https://management.azure.com/subscriptions/{your-sub-id}/resources?api-version=2021-04-01) to get service usage data.

Key Notes

  • Make sure your Azure AD app has the right permissions granted (either user consent or admin consent).
  • For Azure DevOps, even with a valid token, the authenticated user must have the necessary permissions in the Azure DevOps project (e.g., Build Reader) to access build information.
  • If you’re building a backend API instead of a web app, use the On-Behalf-Of flow to exchange user tokens for service-specific tokens.

内容的提问来源于stack exchange,提问作者DFBerry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:05:51