You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AI服务使用az cli列出密钥时出现授权失败问题求助

Azure AI服务使用az cli列出密钥时出现授权失败问题求助

问题背景

我在资源组alper-playground中创建了一个名为alper-azure-ai-service的Azure AI服务资源,并且拥有该资源组的Contributor权限,能够在Azure门户正常访问“密钥和终结点”页面,IAM也显示权限是从资源组继承的。但执行以下AZ CLI命令时却遇到授权失败错误:

az cognitiveservices account keys list --name alper-azure-ai-service --resource-group alper-playground

错误信息:

(AuthorizationFailed) The client 'alper.silistre@{myCompanyEmail}' with object id '{myObjectId}' does not have authorization to perform action 'Microsoft.CognitiveServices/accounts/listKeys/action' over scope '/subscriptions/{subscriptionObjectId}/resourceGroups/alper-playground/providers/Microsoft.CognitiveServices/accounts/alper-azure-ai-service' or the scope is invalid. If access was recently granted, please refresh your credentials.

明明Contributor角色应该包含Microsoft.CognitiveServices/accounts/listKeys/action权限,不知道哪里出了问题。


可能的解决方案和排查方向

作为经常处理Azure权限问题的开发者,我给你几个实用的排查步骤:

  • 刷新CLI凭据缓存
    错误提示里提到了凭据刷新的建议,哪怕你觉得权限早就生效了,也可以试试清除本地缓存后重新登录:

    az account clear
    az login
    

    这一步经常能解决CLI和云端权限不同步的问题。

  • 确认当前订阅上下文正确
    如果你有多个Azure订阅,当前CLI默认使用的订阅可能不是资源所在的订阅。可以用以下命令检查和切换:

    # 查看当前订阅
    az account show
    # 列出所有订阅
    az account list --output table
    # 切换到目标订阅
    az account set --subscription {你的订阅ID}
    
  • 验证实际生效的权限
    用CLI直接查询你在目标资源上的权限分配,确认是否真的包含所需的动作:

    az role assignment list --assignee {你的ObjectId} --resource-group alper-playground --output table
    

    你也可以用权限检查命令直接验证是否能执行listKeys:

    az role assignment check --assignee {你的ObjectId} --scope "/subscriptions/{subscriptionObjectId}/resourceGroups/alper-playground/providers/Microsoft.CognitiveServices/accounts/alper-azure-ai-service" --action "Microsoft.CognitiveServices/accounts/listKeys/action"
    
  • 直接给AI服务资源分配权限
    如果继承的资源组权限存在生效延迟或冲突,可以尝试直接给该AI服务资源分配Cognitive Services Account Contributor角色(这个角色专门针对认知服务资源,权限更精准):

    az role assignment create --assignee {你的ObjectId} --role "Cognitive Services Account Contributor" --scope "/subscriptions/{subscriptionObjectId}/resourceGroups/alper-playground/providers/Microsoft.CognitiveServices/accounts/alper-azure-ai-service"
    
  • 检查租户的条件访问策略
    有些企业租户会配置条件访问策略,限制CLI的访问(比如要求MFA、特定IP范围登录等)。如果前面的步骤都无效,可以联系你的Azure管理员确认是否有相关策略限制了CLI的权限。


备注:内容来源于stack exchange,提问作者Alper Silistre

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.20 12:58:13