You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

删除Azure中PIM角色分配时遇404错误:请求URI无匹配资源

解决PIM角色分配删除时的404错误

测试发现,创建并配置PIM的Entra组被删除后,其PIM配置仍会保留,导致组在Entra中已不存在但在PIM中残留孤立记录。我编写PowerShell脚本先删除PIM角色分配再删除组,但执行时出现如下404错误:

41 |      Remove-MgRoleManagementDirectoryRoleEligibilityScheduleInstance - …
     |      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     | {"message":"No HTTP resource was found that matches the request URI
     | 'https://api.azrbac.mspim.azure.com/api/v3/roleManagement/directory/roleEligibilityScheduleInstances('kxxxxx')?'."}  Status: 404 (NotFound) ErrorCode: UnknownError Date: 2025-04-23T13:05:43  Headers: Cache-Control                 : private Vary
               : Accept-Encoding Strict-Transport-Security     : max-age=31536000 request-id
           : 512xxxxxx client-request-id             : bcxxxxx3 x-ms-ags-diagnostic      

原脚本代码:

param (
    [Parameter(Mandatory = $true)]
    [string]$GroupName
)

$ErrorActionPreference = "stop"
 
# Connect to Graph (if not already)
if (-not (Get-MgContext)) {
    Connect-MgGraph -Scopes "RoleManagement.ReadWrite.Directory", "Group.ReadWrite.All"
}

# Get the group
$group = Get-MgGroup -Filter "displayName eq '$GroupName'"

if (-not $group) {
    Write-Host "Group '$GroupName' not found." -ForegroundColor Red
    return
}

$groupId = $group.Id
Write-Host "Found group: $GroupName (ID: $groupId)" -ForegroundColor Cyan

# Check for PIM role assignments (directory roles)
$assignments = Get-MgRoleManagementDirectoryRoleEligibilityScheduleInstance -Filter "principalId eq '$groupId'" -All
$activeAssignments = Get-MgRoleManagementDirectoryRoleAssignmentScheduleInstance -Filter "principalId eq '$groupId'" -All

# Fix: Combine arrays safely
$totalAssignments = @() + @($assignments) + @($activeAssignments)

if ($totalAssignments.Count -eq 0) {
    Write-Host "No PIM role assignments found. Group will NOT be deleted." -ForegroundColor Yellow
    return
}


# Remove eligible assignments
foreach ($assignment in $assignments) {
    Write-Host "Removing eligible role assignment: $($assignment.Id)" -ForegroundColor Gray
#    Remove-MgRoleManagementDirectoryRoleEligibilityScheduleInstance -RoleEligibilityScheduleInstanceId $assignment.Id
    Remove-MgRoleManagementDirectoryRoleEligibilityScheduleInstance -UnifiedRoleEligibilityScheduleInstanceId $assignment.Id

}

# Remove active assignments
foreach ($assignment in $activeAssignments) {
    Write-Host "Removing active role assignment: $($assignment.Id)" -ForegroundColor Gray
#    Remove-MgRoleManagementDirectoryRoleAssignmentScheduleInstance -RoleAssignmentScheduleInstanceId $assignment.Id
    Remove-MgRoleManagementDirectoryRoleAssignmentScheduleInstance -UnifiedRoleAssignmentScheduleInstanceId $assignment.Id

}

# Wait a moment to ensure removal is propagated
Start-Sleep -Seconds 3

# Delete the group
Write-Host "Deleting group '$GroupName'..." -ForegroundColor Green
Remove-MgGroup -GroupId $groupId -Confirm:$false

Write-Host "Group and PIM assignments removed successfully." -ForegroundColor Green

问题根源

你调用的Remove-MgRoleManagementDirectoryRoleEligibilityScheduleInstance和Remove-MgRoleManagementDirectoryRoleAssignmentScheduleInstance是针对角色调度实例的操作,这些实例是PIM自动生成的动态记录,无法直接删除。正确的操作应该是删除对应的角色资格/分配的定义,而非实例。

修正方案

  1. 替换获取实例的命令,改为获取角色资格和分配的定义:
    • 用Get-MgRoleManagementDirectoryRoleEligibility替代Get-MgRoleManagementDirectoryRoleEligibilityScheduleInstance
    • 用Get-MgRoleManagementDirectoryRoleAssignment替代Get-MgRoleManagementDirectoryRoleAssignmentScheduleInstance
  2. 调整删除命令,使用对应的删除定义的Cmdlet:
    • 用Remove-MgRoleManagementDirectoryRoleEligibility删除资格分配
    • 用Remove-MgRoleManagementDirectoryRoleAssignment删除活动分配

修正后的完整脚本

param (
    [Parameter(Mandatory = $true)]
    [string]$GroupName
)

$ErrorActionPreference = "stop"
 
# Connect to Graph (if not already)
if (-not (Get-MgContext)) {
    Connect-MgGraph -Scopes "RoleManagement.ReadWrite.Directory", "Group.ReadWrite.All"
}

# Get the group
$group = Get-MgGroup -Filter "displayName eq '$GroupName'"

if (-not $group) {
    Write-Host "Group '$GroupName' not found." -ForegroundColor Red
    return
}

$groupId = $group.Id
Write-Host "Found group: $GroupName (ID: $groupId)" -ForegroundColor Cyan

# Check for PIM role assignments (directory roles) - 获取资格和分配的定义而非实例
$eligibilities = Get-MgRoleManagementDirectoryRoleEligibility -Filter "principalId eq '$groupId'" -All
$assignments = Get-MgRoleManagementDirectoryRoleAssignment -Filter "principalId eq '$groupId'" -All

# Combine arrays safely
$totalAssignments = @() + @($eligibilities) + @($assignments)

if ($totalAssignments.Count -eq 0) {
    Write-Host "No PIM role assignments found. Group will NOT be deleted." -ForegroundColor Yellow
    return
}

# Remove eligible assignments
foreach ($eligibility in $eligibilities) {
    Write-Host "Removing eligible role assignment: $($eligibility.Id)" -ForegroundColor Gray
    Remove-MgRoleManagementDirectoryRoleEligibility -UnifiedRoleEligibilityId $eligibility.Id -Confirm:$false
}

# Remove active assignments
foreach ($assignment in $assignments) {
    Write-Host "Removing active role assignment: $($assignment.Id)" -ForegroundColor Gray
    Remove-MgRoleManagementDirectoryRoleAssignment -UnifiedRoleAssignmentId $assignment.Id -Confirm:$false
}

# Wait a moment to ensure removal is propagated
Start-Sleep -Seconds 5

# Delete the group
Write-Host "Deleting group '$GroupName'..." -ForegroundColor Green
Remove-MgGroup -GroupId $groupId -Confirm:$false

Write-Host "Group and PIM assignments removed successfully." -ForegroundColor Green

内容的提问来源于stack exchange,提问作者learner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 07:42:17