建立代理人身份藍圖後,下一步是建立一個或多個代表租戶中 AI 代理人的 代理人身份 。 代理身份建立通常在配置新的 AI 代理時執行。
你可以用兩種方式建立代理人身份:
-
Microsoft Entra 系統管理中心 — 使用管理中心嚮導快速建立個人身份。
-
Microsoft 圖形 API — 建立一個以程式化方式建立代理身份的網路服務,這對於大規模自動化配置非常有用。
如果你想快速建立代理身份以供測試,可以考慮使用 這個Microsoft Entra PowerShell 模組來建立和使用代理身份。
先決條件
要建立代理身份,你需要:
- 一個 特工身份藍圖。 記錄建立過程中的代理身份藍圖應用程式 ID。
- 一個網路服務或應用程式(本地執行或部署到 Azure),負責承載代理身份建立邏輯。 這個先決條件只適用於你以程式化方式建立代理身份時。
使用 Microsoft Entra 管理中心
你可以直接在 Microsoft Entra 系統管理中心 中建立代理身份,方法是選擇現有藍圖並指派擁有者與贊助者。
登入 Microsoft Entra 系統管理中心。
瀏覽至 Entra ID>Agents>代理身分。
選擇新代理身份(預覽)。
在 [基本] 索引標籤上:
在 「擁有者與贊助者 」頁籤中,可以選擇性地新增識別的擁有者與贊助者:
- 選擇 擁有者 欄位旁的鉛筆圖示,以更改或新增可管理此代理身份的使用者。
-
選擇贊助商欄位旁的鉛筆圖示,以更改或新增可贊助此代理身份的使用者。
備註
贊助者可以是使用者、動態會員群組或 Microsoft 365 群組。 安全群組與可角色指派群組不被支援作為贊助者。
選取 [下一步]。
檢視你的設定,然後選擇 建立。
選擇 「完成 」以退出精靈,或選擇 「前往代理身份 」以查看該身份的詳細頁面或設定更多設定。
在接下來的步驟中,你將學習如何使用 Microsoft 圖形 API 和 Microsoft.Identity.Web,以程式化的方式建立代理身份。 先取得存取權杖,然後呼叫建立 API。
使用代理身份藍圖取得存取令牌。
你使用代理人身份藍圖來建立每個代理人身份。 使用您的代理身份藍圖向 Microsoft Entra 申請存取權杖:
使用受管理身份作為憑證時,您必須先使用您的管理身份取得存取權杖。 管理身份憑證可以從計算環境中本地暴露的 IP 位址請求。
詳情請參閱管理身份文件。
GET http://169.254.169.254/metadata/identity/oauth2/token?api-version=2019-08-01&resource=api://AzureADTokenExchange/.default
Metadata: True
取得管理身份的權杖後,請申請代理身份藍圖的權杖:
POST https://login.microsoftonline.com/<your-tenant-id>/oauth2/v2.0/token
Content-Type: application/x-www-form-urlencoded
client_id=<agent-blueprint-id>
scope=https://graph.microsoft.com/.default
client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer
client_assertion=<msi-token>
grant_type=client_credentials
在本地開發中使用用戶端秘密時,也可以使用client_secret參數來代替client_assertion和client_assertion_type。
安裝 Microsoft。Identity.Web:
dotnet add package Microsoft.Identity.Web
Microsoft。Identity.Web 包含一個介面,能自動請求存取權杖並將其附加到外站 HTTP 請求。 使用Microsoft。Identity.Web,你可以跳到下一步。
建立代理人身份
利用前一步取得的存取權杖,你現在可以在租戶中建立代理身份。 代理身份的建立可能因應多種不同事件或觸發條件而發生,例如使用者選擇按鈕來建立新的代理。 我們建議你為每位代理人建立一個代理人身份,但你可能會根據需求選擇不同的方式。
使用 @odata.type時務必包含 OData-Version 標頭。
POST https://graph.microsoft.com/beta/serviceprincipals/Microsoft.Graph.AgentIdentity
OData-Version: 4.0
Content-Type: application/json
Authorization: Bearer <token>
{
"displayName": "My Agent Identity",
"agentIdentityBlueprintId": "<my-agent-blueprint-id>",
"sponsors@odata.bind": [
"https://graph.microsoft.com/v1.0/users/<id>",
"https://graph.microsoft.com/v1.0/groups/<group-id>"
]
}
備註
指派團體為贊助人時,僅接受 受支持的團體類型 。 群組不被當作擁有者來支持。
用Microsoft.Identity.Web 執行 Microsoft 圖形 API 請求以建立代理身份,請加入以下 MISE 設定檔:
警告
由於安全風險,客戶端秘密不應在生產環境中作為代理身份藍圖的客戶端憑證使用。 相反地,應使用更安全的認證方法,例如 聯邦身份憑證(FIC)搭配管理身份 或用戶端憑證。 這些方法透過消除直接在應用程式配置中儲存敏感秘密的需求,提升安全性。
{
"AzureAd": {
"Instance": "https://login.microsoftonline.com/",
"TenantId": "<your-tenant-id>",
"ClientId": "<my-agent-blueprint-id>",
"Scopes": "access_agent",
"ClientCredentials": [
{
"SourceType": "ClientSecret",
"ClientSecret": "your-client-secret"
}
]
},
"DownstreamApis": {
"agent-identity": {
"BaseUrl": "https://graph.microsoft.com",
"RelativePath": "/beta/serviceprincipals/Microsoft.Graph.AgentIdentity",
"Scopes": ["00000003-0000-0000-c000-000000000000/.default"],
"RequestAppToken": true
}
}
}
ASP.NET Core 應用程式的程式碼(Program.cs)範例如下:
using System.Text.Json.Serialization;
using Microsoft.Identity.Abstractions;
using Microsoft.Identity.Web;
using Microsoft.Identity.Web.Resource;
using Microsoft.IdentityModel.S2S.Extensions.AspNetCore;
var builder = WebApplication.CreateBuilder(args);
// Add services to the container.
builder.Services.AddMicrosoftIdentityWebApiAuthentication(builder.Configuration)
.EnableTokenAcquisitionToCallDownstreamApi();
builder.Services.AddInMemoryTokenCaches();
var app = builder.Build();
app.UseHttpsRedirection();
app.UseAuthentication();
app.UseAuthorization();
// Create an Agent identity
app.MapGet("/create-agent-identity", async (HttpContext httpContext) =>
{
try
{
// Get the service to call the downstream API (preconfigured in the appsettings.json file)
IDownstreamApi downstreamApi = httpContext.RequestServices.GetRequiredService<IDownstreamApi>();
// Call the downstream API with a POST request to create an Agent Identity
var jsonResult = await downstreamApi.PostForAppAsync<AgentIdentity, AgentIdentity>(
"agent-identity",
new AgentIdentity
{
displayName = "My agent identity",
agentIdentityBlueprintId = "<my-agent-blueprint-id>",
sponsorsOdataBind = new[] { "https://graph.microsoft.com/v1.0/users/<id>" }
});
return jsonResult?.id;
}
catch (Exception ex)
{
return ex.Message;
}
});
app.Run();
// Type declarations must follow the top-level statements.
public class AgentIdentity
{
[JsonPropertyName("@odata.type")]
public string @odata_type { get; set; } = "#Microsoft.Graph.AgentIdentity";
[JsonPropertyName("displayName")]
public string? displayName { get; set; }
[JsonPropertyName("agentIdentityBlueprintId")]
public string? agentIdentityBlueprintId { get; set; }
[JsonPropertyName("id")]
public string? id { get; set; }
[JsonPropertyName("sponsors@odata.bind")]
public string[]? sponsorsOdataBind { get; set; }
[JsonPropertyName("owners@odata.bind")]
public string[]? ownersOdataBind { get; set; }
}
刪除代理身份
當代理被解除配置或銷毀時,你的服務也應該刪除相關的代理身份:
DELETE https://graph.microsoft.com/beta/serviceprincipals/<agent-identity-id>
OData-Version: 4.0
Content-Type: application/json
Authorization: Bearer <token>
// Delete an Agent identity
app.MapGet("/delete-agent-identity", async (HttpContext httpContext, string id) =>
{
// Get the service to call the downstream API (preconfigured in the appsettings.json file)
IDownstreamApi downstreamApi = httpContext.RequestServices.GetRequiredService<IDownstreamApi>();
// Call the downstream API with a DELETE request to remove an Agent Identity
var jsonResult = await downstreamApi.DeleteForAppAsync<string, string>(
"agent-identity",
null!,
options =>
{
options.RelativePath += $"/{id}"; // Specify the ID of the agent identity to delete
});
return jsonResult;
});
相關內容