删除Azure中PIM角色分配时遇404错误:请求URI无匹配资源
解决PIM角色分配删除时的404错误
测试发现,创建并配置PIM的Entra组被删除后,其PIM配置仍会保留,导致组在Entra中已不存在但在PIM中残留孤立记录。我编写PowerShell脚本先删除PIM角色分配再删除组,但执行时出现如下404错误:
41 | Remove-MgRoleManagementDirectoryRoleEligibilityScheduleInstance - … | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ | {"message":"No HTTP resource was found that matches the request URI | 'https://api.azrbac.mspim.azure.com/api/v3/roleManagement/directory/roleEligibilityScheduleInstances('kxxxxx')?'."} Status: 404 (NotFound) ErrorCode: UnknownError Date: 2025-04-23T13:05:43 Headers: Cache-Control : private Vary : Accept-Encoding Strict-Transport-Security : max-age=31536000 request-id : 512xxxxxx client-request-id : bcxxxxx3 x-ms-ags-diagnostic
原脚本代码:
param ( [Parameter(Mandatory = $true)] [string]$GroupName ) $ErrorActionPreference = "stop" # Connect to Graph (if not already) if (-not (Get-MgContext)) { Connect-MgGraph -Scopes "RoleManagement.ReadWrite.Directory", "Group.ReadWrite.All" } # Get the group $group = Get-MgGroup -Filter "displayName eq '$GroupName'" if (-not $group) { Write-Host "Group '$GroupName' not found." -ForegroundColor Red return } $groupId = $group.Id Write-Host "Found group: $GroupName (ID: $groupId)" -ForegroundColor Cyan # Check for PIM role assignments (directory roles) $assignments = Get-MgRoleManagementDirectoryRoleEligibilityScheduleInstance -Filter "principalId eq '$groupId'" -All $activeAssignments = Get-MgRoleManagementDirectoryRoleAssignmentScheduleInstance -Filter "principalId eq '$groupId'" -All # Fix: Combine arrays safely $totalAssignments = @() + @($assignments) + @($activeAssignments) if ($totalAssignments.Count -eq 0) { Write-Host "No PIM role assignments found. Group will NOT be deleted." -ForegroundColor Yellow return } # Remove eligible assignments foreach ($assignment in $assignments) { Write-Host "Removing eligible role assignment: $($assignment.Id)" -ForegroundColor Gray # Remove-MgRoleManagementDirectoryRoleEligibilityScheduleInstance -RoleEligibilityScheduleInstanceId $assignment.Id Remove-MgRoleManagementDirectoryRoleEligibilityScheduleInstance -UnifiedRoleEligibilityScheduleInstanceId $assignment.Id } # Remove active assignments foreach ($assignment in $activeAssignments) { Write-Host "Removing active role assignment: $($assignment.Id)" -ForegroundColor Gray # Remove-MgRoleManagementDirectoryRoleAssignmentScheduleInstance -RoleAssignmentScheduleInstanceId $assignment.Id Remove-MgRoleManagementDirectoryRoleAssignmentScheduleInstance -UnifiedRoleAssignmentScheduleInstanceId $assignment.Id } # Wait a moment to ensure removal is propagated Start-Sleep -Seconds 3 # Delete the group Write-Host "Deleting group '$GroupName'..." -ForegroundColor Green Remove-MgGroup -GroupId $groupId -Confirm:$false Write-Host "Group and PIM assignments removed successfully." -ForegroundColor Green
问题根源
你调用的Remove-MgRoleManagementDirectoryRoleEligibilityScheduleInstance和Remove-MgRoleManagementDirectoryRoleAssignmentScheduleInstance是针对角色调度实例的操作,这些实例是PIM自动生成的动态记录,无法直接删除。正确的操作应该是删除对应的角色资格/分配的定义,而非实例。
修正方案
- 替换获取实例的命令,改为获取角色资格和分配的定义:
- 用
Get-MgRoleManagementDirectoryRoleEligibility替代Get-MgRoleManagementDirectoryRoleEligibilityScheduleInstance - 用
Get-MgRoleManagementDirectoryRoleAssignment替代Get-MgRoleManagementDirectoryRoleAssignmentScheduleInstance
- 用
- 调整删除命令,使用对应的删除定义的Cmdlet:
- 用
Remove-MgRoleManagementDirectoryRoleEligibility删除资格分配 - 用
Remove-MgRoleManagementDirectoryRoleAssignment删除活动分配
- 用
修正后的完整脚本
param ( [Parameter(Mandatory = $true)] [string]$GroupName ) $ErrorActionPreference = "stop" # Connect to Graph (if not already) if (-not (Get-MgContext)) { Connect-MgGraph -Scopes "RoleManagement.ReadWrite.Directory", "Group.ReadWrite.All" } # Get the group $group = Get-MgGroup -Filter "displayName eq '$GroupName'" if (-not $group) { Write-Host "Group '$GroupName' not found." -ForegroundColor Red return } $groupId = $group.Id Write-Host "Found group: $GroupName (ID: $groupId)" -ForegroundColor Cyan # Check for PIM role assignments (directory roles) - 获取资格和分配的定义而非实例 $eligibilities = Get-MgRoleManagementDirectoryRoleEligibility -Filter "principalId eq '$groupId'" -All $assignments = Get-MgRoleManagementDirectoryRoleAssignment -Filter "principalId eq '$groupId'" -All # Combine arrays safely $totalAssignments = @() + @($eligibilities) + @($assignments) if ($totalAssignments.Count -eq 0) { Write-Host "No PIM role assignments found. Group will NOT be deleted." -ForegroundColor Yellow return } # Remove eligible assignments foreach ($eligibility in $eligibilities) { Write-Host "Removing eligible role assignment: $($eligibility.Id)" -ForegroundColor Gray Remove-MgRoleManagementDirectoryRoleEligibility -UnifiedRoleEligibilityId $eligibility.Id -Confirm:$false } # Remove active assignments foreach ($assignment in $assignments) { Write-Host "Removing active role assignment: $($assignment.Id)" -ForegroundColor Gray Remove-MgRoleManagementDirectoryRoleAssignment -UnifiedRoleAssignmentId $assignment.Id -Confirm:$false } # Wait a moment to ensure removal is propagated Start-Sleep -Seconds 5 # Delete the group Write-Host "Deleting group '$GroupName'..." -ForegroundColor Green Remove-MgGroup -GroupId $groupId -Confirm:$false Write-Host "Group and PIM assignments removed successfully." -ForegroundColor Green
内容的提问来源于stack exchange,提问作者learner
相关产品推荐
相关产品推荐

