首次通过API访问Microsoft Dynamics 365:仅用账号密码是否可行?
First off, let’s get straight to the point: you can’t connect to the Dynamics 365 Web API using only a username and password—you’ll need those AUTHORIZATION_URL, clientid, and related authentication endpoints too. Here’s why and how to get set up:
Why You Need Those Extra Parameters
Dynamics 365 Online relies on OAuth 2.0 for secure authentication, which requires an Azure Active Directory (Azure AD) registered application to act as a trusted intermediary between your code and the Dynamics 365 instance. Those parameters (clientid, authorization/token endpoints) are tied directly to this registered app—they let Azure AD verify that your code has permission to access the Dynamics 365 data.
Step-by-Step to Get the Required Info & Connect
1. Register an App in Azure AD
You’ll need to create a registered application in the Azure Portal (you’ll need Azure AD admin access or permission to register apps in your organization):
- Navigate to Azure Active Directory → App Registrations → New Registration.
- Name your app, set a redirect URI (for testing, use something like
http://localhost:8000—it doesn’t need to be a live site, just a placeholder for the OAuth flow). - After registering, copy the Application (client) ID—this is your
clientid. - Next, go to API Permissions → Add a Permission → select Dynamics CRM → choose the delegated permission
user_impersonation(this lets your app act on behalf of the user). - Grant admin consent for your organization (if required by your tenant settings).
2. Locate the Authorization & Token Endpoints
In your registered app’s overview page, click the Endpoints button. You’ll need two critical URLs from here:
- The OAuth 2.0 authorization endpoint (this becomes your
AUTHORIZATION_URL) - The OAuth 2.0 token endpoint (used to request access tokens for the API)
3. Use the Resource Owner Password Credentials (ROPC) Flow (Testing Only)
Since you have a username and password, you can use the ROPC flow to fetch an access token. Important note: Microsoft doesn’t recommend this flow for production (it’s less secure and won’t work for users with Multi-Factor Authentication enabled), but it’s a quick way to test your connection.
Here’s a simplified Python example using the requests library:
import requests # Replace these with your actual values client_id = "YOUR_REGISTERED_APP_CLIENT_ID" username = "YOUR_DYNAMICS_USERNAME" password = "YOUR_DYNAMICS_PASSWORD" token_endpoint = "YOUR_AZURE_AD_TOKEN_ENDPOINT" dynamics_instance_url = "https://your-org-name.crm.dynamics.com" # Request access token token_payload = { "grant_type": "password", "client_id": client_id, "username": username, "password": password, "resource": dynamics_instance_url } response = requests.post(token_endpoint, data=token_payload) access_token = response.json()["access_token"] # Call the Dynamics 365 Web API headers = { "Authorization": f"Bearer {access_token}", "OData-MaxVersion": "4.0", "OData-Version": "4.0", "Accept": "application/json", "Content-Type": "application/json; charset=utf-8" } # Example: Fetch a list of accounts api_response = requests.get(f"{dynamics_instance_url}/api/data/v9.2/accounts", headers=headers) print(api_response.json())
Key Takeaways
- Registering an Azure AD app is non-negotiable—those
clientidand endpoint parameters are mandatory for OAuth 2.0 authentication. - For production environments, use a more secure flow like the Authorization Code Flow (which supports MFA and follows best practices).
内容的提问来源于stack exchange,提问作者Salman Shaikh

