如何通过Graph API筛选排除Entra ID中的Microsoft应用?
在Entra ID中排除Microsoft应用的Graph API实现方法
要排除Entra ID中的Microsoft官方应用,可通过ServicePrincipal对象的专属属性进行筛选,具体方法如下:
方法1:通过应用所有者组织ID排除
Microsoft官方应用的所有者组织ID为固定值 9188040d-6c67-4c5b-b112-36a304b66dad,直接在Graph API查询中排除该ID对应的应用即可:
GET https://graph.microsoft.com/v1.0/servicePrincipals?$filter=appOwnerOrganizationId ne '9188040d-6c67-4c5b-b112-36a304b66dad'
方法2:通过发布者名称排除
如果需要更灵活地排除各类Microsoft发布的应用,可结合publisherName属性筛选:
GET https://graph.microsoft.com/v1.0/servicePrincipals?$filter=publisherName ne 'Microsoft' and publisherName ne 'Microsoft Corporation'
若要排除所有名称以「Microsoft」开头的发布者应用,可使用模糊匹配:
GET https://graph.microsoft.com/v1.0/servicePrincipals?$filter=not startswith(publisherName, 'Microsoft')
注意:部分第三方应用可能在发布者名称中包含「Microsoft」关键词,需根据实际业务场景调整筛选规则。
你提到的「Application Filter」对应的中文翻译为:应用筛选器
内容的提问来源于stack exchange,提问作者Megha Bachani
相关产品推荐
相关产品推荐

