【问题标题】:How does an admin grant access to an app?管理员如何授予对应用程序的访问权限?
【发布时间】:2017-11-09 00:18:21
【问题描述】:

我制作了一个使用 Microsoft Graph 和范围 profile、openid、email 和 User.Read 的 Web 应用程序。这很好用。

我现在想包括offline_access、User.Read、Mail.Send、Calendars.ReadWrite、Directory.ReadWrite.All、Directory.AccessAsUser.All、User.Read.All、Files.ReadWrite.All、Files.Read、Files.ReadWrite 987654337@ 范围。

当我尝试登录时,我收到消息:

您无法访问此应用程序。

教程示例应用程序需要访问组织中只有管理员才能授予的资源的权限。请先让管理员授予此应用的权限,然后才能使用它。

我在https://apps.dev.microsoft.com/ 注册了应用程序并设置了这些图表权限:

使用PHP,我使用如下

use Microsoft\Graph\Graph;
use Microsoft\Graph\Model;
const CLIENT_ID          = 'xxx';
const CLIENT_SECRET      = 'xxx';
const REDIRECT_URI       = 'xxxx';
const AUTHORITY_URL      = 'https://login.microsoftonline.com/common';
const AUTHORIZE_ENDPOINT = '/oauth2/v2.0/authorize';
const TOKEN_ENDPOINT     = '/oauth2/v2.0/token';
const SCOPES             = 'profile openid email offline_access User.Read Mail.Send Calendars.ReadWrite Directory.ReadWrite.All Directory.AccessAsUser.All User.Read.All Files.ReadWrite.All Files.Read Files.ReadWrite Sites.Read.All';

并创建authorisationUrl

$authorizationUrl = $provider->getAuthorizationUrl();

那么,我怎样才能让管理员授予访问权限?

【问题讨论】:

    标签: azure-active-directory microsoft-graph-api


    【解决方案1】:

    为了获得管理员同意,您需要让租户的管理员针对 /adminconsent 进行身份验证。此 URL 的原型是(换行符仅供阅读):

    https://login.microsoftonline.com/common/adminconsent?
    client_id=[APPLICATION ID]&redirect_uri=[REDIRECT URI]
    

    我已就此撰写了一篇博文,将帮助您了解其工作原理:v2 Endpoint and Admin Consent。

    【讨论】:

    • 嗨,马克。谢谢你的文章。我仍然不清楚如何纠正错误。
    猜你喜欢
    • 2012-03-15
    • 1970-01-01
    • 2012-07-12
    • 1970-01-01
    • 1970-01-01
    • 2015-06-19
    • 1970-01-01
    • 2015-11-14
    • 1970-01-01
    相关资源
    最近更新 更多