Logic App Entra Get User动作忽略$select无法返回employeeId等属性
在Logic App中获取Entra用户的employeeId和extensionAttributes字段
问题原因
Entra(Azure AD)连接器的内置Get User动作默认仅返回基础用户属性,且部分版本的连接器会忽略自定义的$select查询参数——因为它对Graph API的调用做了封装,不支持直接传递这类参数。
解决方案
方案1:调整Entra连接器的参数设置(优先尝试)
如果使用可视化编辑器,不要直接修改JSON代码,而是:
- 打开
Get User动作的配置面板 - 查找是否有**"选择属性"**或类似参数选项(新版连接器通常会提供该配置项)
- 在选项中输入需要的属性列表:
id,displayName,mail,userPrincipalName,employeeId,extensionAttributes - 保存配置后重新运行,确认是否返回目标字段
若必须使用代码视图,部分连接器要求用parameters而非queries传递选择参数,可尝试修改动作定义:
"Get_user": { "type": "ApiConnection", "inputs": { "host": { "connection": { "name": "@parameters('$connections')['azuread']['connectionId']" } }, "method": "get", "path": "/v1.0/users/@{encodeURIComponent(triggerBody()?['Assignment']?['Target']?['Id'])}", "parameters": { "$select": "id,displayName,mail,userPrincipalName,employeeId,extensionAttributes" } } }
方案2:直接调用Microsoft Graph API(更可靠)
如果连接器方案无效,改用托管身份直接调用Graph API,步骤如下:
- 在Logic App中添加HTTP动作
- 配置动作参数:
- 方法:
GET - URI:
https://graph.microsoft.com/v1.0/users/@{encodeURIComponent(triggerBody()?['Assignment']?['Target']?['Id'])}?$select=id,displayName,mail,userPrincipalName,employeeId,extensionAttributes - 身份验证类型:
托管标识 - 资源:
https://graph.microsoft.com
- 方法:
- 配置权限:
- 进入Entra ID,找到Logic App的系统托管身份
- 添加Microsoft Graph的应用权限:
User.Read.All(若仅需读取单个用户,User.Read也可,但User.Read.All兼容性更强) - 授予管理员同意
对应的动作JSON定义:
"Get_User_Details": { "type": "Http", "inputs": { "method": "GET", "uri": "https://graph.microsoft.com/v1.0/users/@{encodeURIComponent(triggerBody()?['Assignment']?['Target']?['Id'])}?$select=id,displayName,mail,userPrincipalName,employeeId,extensionAttributes", "authentication": { "type": "ManagedServiceIdentity", "resource": "https://graph.microsoft.com" } } }
总结
- 优先尝试调整连接器的可视化参数或修改代码中的参数传递方式
- 若连接器限制无法突破,直接调用Graph API是更灵活可控的方案,且能完全自定义返回字段
内容的提问来源于stack exchange,提问作者ex4
相关产品推荐
相关产品推荐

