You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在M365 Agents SDK中用Key Vault证书实现身份验证?

如何通过M365 Agents SDK使用Key Vault中的证书配置身份验证?

可以实现。M365 Agents SDK的MSAL认证配置支持直接传入X509Certificate2对象,因此你可以复用Bot Framework SDK中从Key Vault加载证书的逻辑,将证书加载后注入到Agents SDK的认证配置中。

具体实现步骤:

  1. 安装必要的NuGet包
    确保项目安装访问Azure Key Vault所需的依赖包:

    Install-Package Azure.Security.KeyVault.Certificates
    Install-Package Azure.Identity
    
  2. 编写Key Vault证书加载逻辑
    创建方法从Key Vault获取证书并转换为X509Certificate2对象:

    using Azure.Identity;
    using Azure.Security.KeyVault.Certificates;
    using System.Security.Cryptography.X509Certificates;
    
    public static async Task<X509Certificate2> LoadCertificateFromKeyVault(string vaultUri, string certName)
    {
        var certClient = new CertificateClient(new Uri(vaultUri), new DefaultAzureCredential());
        var certResponse = await certClient.GetCertificateAsync(certName);
        
        // 获取包含私钥的证书版本
        var certWithPrivateKey = await certClient.GetCertificateVersionAsync(certResponse.Value.Name, certResponse.Value.Version);
        return new X509Certificate2(certWithPrivateKey.Value.Cer);
    }
    
  3. 配置M365 Agents的MSAL认证
    在服务配置中,将加载的证书传入MSALAuthConfigurationOptions的Certificate属性:

    var builder = WebApplication.CreateBuilder(args);
    
    // 从配置读取Key Vault信息并加载证书
    var keyVaultUri = builder.Configuration["KeyVault:Uri"];
    var certName = builder.Configuration["KeyVault:CertificateName"];
    var certificate = await LoadCertificateFromKeyVault(keyVaultUri, certName);
    
    // 配置M365 Agents
    builder.Services.AddM365Agents(options =>
    {
        options.MSALAuth = new MSALAuthConfigurationOptions
        {
            ClientId = builder.Configuration["AzureAd:ClientId"],
            TenantId = builder.Configuration["AzureAd:TenantId"],
            Certificate = certificate // 使用Key Vault中的证书
        };
    });
    
    // 其他应用配置...
    var app = builder.Build();
    

注意事项:

  • 确保你的应用(本地开发账号或生产环境托管身份/服务主体)拥有Key Vault的Certificate Reader或Key Vault Secrets User权限,才能读取证书。
  • 本地开发时,可通过Azure CLI登录获取身份凭证;生产环境建议使用托管身份,避免硬编码密钥。

内容的提问来源于stack exchange,提问作者Medha Gupta

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 16:57:21