【问题标题】:How to authenticate to Azure Active Directory without user interaction?如何在没有用户交互的情况下向 Azure Active Directory 进行身份验证?
【发布时间】:2017-09-19 19:48:21
【问题描述】:

我希望在没有用户交互的情况下获取访问令牌,以便自动调用 Azure 服务(计算、网络等)的 REST API。 In the documentation,列出了几种认证场景。最适合我的用例的是“Daemon or Server Application to Web API”。

我按照instructions 请求访问令牌:首先我在我的 Azure Active Directory 中注册了一个应用程序。然后我创建了一个与应用程序 ID(client_id 参数)关联的密钥(client_secret 参数)。我还获得了 App ID URI(资源参数)。我使用所有这些参数向我的 Azure AD 的 /token 端点创建了一个 POST 请求。但是我收到以下错误消息:

{
    "code":"InvalidAuthenticationTokenAudience",
    "message":"The access token has been obtained from wrong audience or resource 'https://solutionsmosaixsoft.onmicrosoft.com/<APP_ID_URI>'. It should exactly match (including forward slash) with one of the allowed audiences 'https://management.core.windows.net/','https://management.azure.com/'."
}

我做错了什么?我是否将资源参数设置为错误的值?

【问题讨论】:

    标签: rest azure authentication oauth-2.0 azure-active-directory


    【解决方案1】:

    resource 参数告诉您的应用程序从哪里获取令牌(请求访问令牌的资源的标识符)。如果你想获取一个token来调用Azure Service Management API,你可以将资源设置为https://management.core.windows.net/。

    编辑:

    如果您要调用的 API 是 Microsoft 提供的 API,则资源是已知的,例如:

    如果您想调用您创建的 API 应用程序,您可以使用资源 WebAPI 的客户端 ID 或应用程序 ID URI(在 Azure 管理门户的 Azure AD 应用程序的配置选项卡中找到它们)。

    您可以参考以下链接获取代码示例:

    https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-code-samples

    【讨论】:

    • 在this page上,说resources参数是:Enter the App ID URI of the receiving web service. To find the App ID URI, in the Azure Management Portal, click Active Directory, click the directory, click the application, and then click Configure.这个信息有错吗?
    • @GlebBillig,我已经编辑了答案来解释你的问题,请检查一下。
    【解决方案2】:

    您需要向令牌端点发出 POST 请求。

    resource 参数必须是您要访问的 API 的资源 URI,而不是您的。

    • Azure AD 图形 API:https://graph.windows.net/
    • Microsoft 图形 API:https://graph.microsoft.com/

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2017-04-06
      • 1970-01-01
      相关资源
      最近更新 更多