【问题标题】:Error: Error Deleting User with ID XXX graphrbac.UsersClient#Delete Authorization_RequestDenied - Insufficient privileges to complete the operation错误:删除 ID 为 XXX 的用户时出错 graphrbac.UsersClient#Delete Authorization_RequestDenied - 权限不足,无法完成操作
【发布时间】:2020-07-17 08:03:27
【问题描述】:

我已经创建了我的服务原则并添加了所有必要的权限,以便在我的 Azure Active Directory 中读取和写入 用户。

我在上面运行terraform plan 和terraform apply,它运行良好。

但是,每当我尝试销毁 (terraform destroy) 资源 (azuread_user) 以删除 AD 用户时,我都会收到此错误

我做错了什么?任何帮助将不胜感激。


更新:添加.tf文件

provider "azuread" {
  version = "~> 0.11"
  subscription_id= var.ARM_SUBSCRIPTION_ID
  client_id       = var.ARM_CLIENT_ID
  client_secret   = var.ARM_CLIENT_SECRET
  tenant_id       = var.ARM_TENANT_ID
}

resource "azuread_user" "main-user" {
  user_principal_name = var.email
  display_name        = var.name
  password            = var.password
}

【问题讨论】:

  • 请在.tf 文件中分享您的 terraform 配置,该文件将删除 AAD 用户。
  • 您使用的是哪个版本的 terraform?
  • 另外,请确保NOTE: If you're authenticating using a Service Principal then it must have permissions to Directory.ReadWrite.All within the Windows Azure Active Directory API.
  • @AllenWu - 我已经添加了我的.tf 文件作为更新。
  • @AmitBaranes - Terraform v0.12.28

标签: azure active-directory azure-active-directory terraform


【解决方案1】:

看起来与服务主体拥有的权限有关的问题,我建议创建一个具有 Azure AD 完全权限的新问题。检查此理论的一种方法是尝试使用 az CLI 删除由 terraform 创建的用户。

首先,使用现有的服务主体:

az login --service-principal --username APP_ID --password PASSWORD --tenant TENANT_ID

稍后,尝试通过运行删除用户:

az ad user delete --id %USER_ID%

如果命令失败,请创建新的服务主体并将管理员权限分配给 Azure Active Directory。

另外,来自terraform docs - NOTE: If you're authenticating using a Service Principal then it must have permissions to Directory.ReadWrite.All within the Windows Azure Active Directory API

【讨论】:

  • 创建了一个新的 SP 但它仍然存在 :(
  • 刚刚看到批准的答案,看起来我在权限问题上走对了。很高兴这个问题得到了解决。
  • @JohnErbynn 顺便说一句,请小心授予全局管理员对 terraform 的权限。在这种情况下,您可以授予 Terraform 对任何资源的权限。在我看来是登机。
【解决方案2】:

我对你的脚本进行了测试,发现如果我们在Azure AD Graph下只给Directory.ReadWrite.AllDelegated权限,就只能创建AAD用户。当我尝试使用terraform destroy 删除它时,我得到了和你一样的错误。

所以我尝试了另一种方法:将 全局管理员 角色分配给 Azure 门户中的服务主体。这样我就可以成功删除用户了。

在此处查看参考:Method 1: Directory Roles (recommended)。

【讨论】:

  • 对。这在为 SP 分配了Global Administrator 角色后修复了它……感谢@Allen Wu 的“T”……为我节省了很多时间。 +1
  • 哇,这就像把 GODMODE 给你的 SP。你确定要去那里?如果有人拿到这些凭据......对不起,由于严重的安全风险,请投反对票
猜你喜欢
  • 2019-10-30
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2018-01-09
  • 1970-01-01
  • 1970-01-01
  • 2017-03-31
相关资源
最近更新 更多