You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell调用XrmTooling的Get-CrmConnection连接Dynamics CRM失败

PowerShell调用XrmTooling的Get-CrmConnection连接Dynamics CRM失败

你好,根据你描述的情况——之前正常运行的连接函数现在抛出*Failed to connect to CRM: Invalid Login Information : The HTTP request is unauthorized with client authentication scheme 'Anonymous'*错误,而且已经确认$clientId、$clientSecret和$url都是正确的,我整理了几个可能的排查方向和解决方案,你可以逐一尝试:

可能的排查与修复方案

1. 检查模块版本兼容性

你当前使用的Microsoft.Xrm.Tooling.CrmConnector.PowerShell模块可能自动更新到了新版本,和你的Dynamics CRM环境出现兼容性问题。可以尝试回退到之前可用的旧版本:

# 先卸载当前模块(如果需要)
Uninstall-Module $moduleName -Force -ErrorAction SilentlyContinue
# 安装一个已知兼容的旧版本,比如2.3.0版本(请根据你之前可用时的版本调整)
Install-Module $moduleName -Scope CurrentUser -RequiredVersion 2.3.0 -Force

2. 确认Azure AD应用权限配置是否变更

虽然你确认了Client ID和Secret正确,但有可能应用的权限被修改或管理员同意被撤销:

  • 登录Azure门户找到对应的应用注册,检查是否包含Dynamics CRM相关权限(比如Dynamics CRM User Impersonation或Organization.ReadWrite.All)
  • 确认这些权限已经完成管理员同意授权,未授权的权限会导致认证失败

3. 补充连接字符串的额外认证参数

默认连接参数可能不足以应对某些环境,尝试添加RequireNewInstance或明确指定OAuth端点:

# 替换your-tenant-id为你的Azure租户ID或租户域名(如contoso.onmicrosoft.com)
$connectionString = "AuthType=ClientSecret;url=$url;ClientId=$clientId;ClientSecret=$clientSecret;RequireNewInstance=true;OAuthUri=https://login.microsoftonline.com/your-tenant-id/oauth2/token"

4. 扩展TLS协议支持范围

你已经设置了TLS1.2,但部分环境可能需要同时启用更高版本的协议:

[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.SecurityProtocolType]::Tls12 -bor [System.Net.SecurityProtocolType]::Tls13

5. 排查网络拦截问题

如果运行环境在企业内网,可能存在代理或防火墙拦截请求:

  • 尝试设置PowerShell代理(如果需要):
$proxyAddress = "http://your-proxy-server:port"
[System.Net.WebRequest]::DefaultWebProxy = New-Object System.Net.WebProxy($proxyAddress, $true)
[System.Net.WebRequest]::DefaultWebProxy.Credentials = [System.Net.CredentialCache]::DefaultCredentials
  • 或者切换到非内网环境测试,排除网络因素的影响

额外调试步骤

你可以启用XrmTooling的详细日志,获取更精准的错误细节:

# 指定日志存储路径
$logPath = "C:\temp\CrmConnector.log"
# 添加日志参数到连接字符串
$connectionString = "AuthType=ClientSecret;url=$url;ClientId=$clientId;ClientSecret=$clientSecret;LogLevel=Verbose;LogFile=$logPath"

运行后查看日志文件,里面会记录认证过程中的具体问题,比如租户ID不匹配、权限校验失败等信息

备注:内容来源于stack exchange,提问作者imran chowdhury

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 08:12:59