You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过REST API或PowerShell获取Azure Entra用户同意权限设置状态?

Yes, you can use the Microsoft Graph API to automate checking the tenant-wide user consent setting you’re targeting.

API Endpoint & Request

Send a GET request to this endpoint:

GET https://graph.microsoft.com/v1.0/policies/authorizationPolicy

Required Permissions

Your authenticated request needs one of these permissions:

  • Delegated: Policy.Read.All or Directory.Read.All
  • Application: Policy.Read.All or Directory.Read.All

Interpret the Response

Look for the allowUserConsentForApps boolean property in the response:

  • false: User consent for apps accessing company data is disabled (matches your required rule)
  • true: User consent is enabled

Example response snippet:

{
  "id": "authorizationPolicy",
  "allowUserConsentForApps": false,
  "allowUserConsentForRiskyApps": false,
  "allowAdminConsentForApps": true,
  // Additional policy properties...
}

Bonus: PowerShell Alternative

If you still want a PowerShell solution using Graph, here’s a quick script:

# Connect to Microsoft Graph with required permissions
Connect-MgGraph -Scopes "Policy.Read.All"

# Retrieve the authorization policy
$authPolicy = Get-MgPolicyAuthorizationPolicy

# Check the user consent setting
if ($authPolicy.AllowUserConsentForApps -eq $false) {
    Write-Host "User consent is disabled (compliant with your rule)"
} else {
    Write-Host "User consent is enabled (non-compliant)"
}

内容的提问来源于stack exchange,提问作者Trisha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.11 11:13:12