You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何批量修改Microsoft Defender中500+自定义检测规则的设备组?

批量更新Microsoft Defender自定义检测规则的设备组方案

完全可以通过Microsoft Graph API + PowerShell实现批量修改,手动处理500+条规则效率极低,自动化是最优解。以下是具体实现步骤和脚本:

前置准备

  • 权限要求:需要拥有Security Administrator、Global Administrator角色,或自定义权限包含SecurityDetection.ReadWrite.All权限
  • 安装模块:确保已安装Microsoft Graph PowerShell Security模块:
    Install-Module Microsoft.Graph.Security -Force -AllowClobber
    

步骤1:获取目标设备组ID

先查询所有设备组,找到你要设置的新设备组ID:

# 连接到Microsoft Graph
Connect-MgGraph -Scopes "SecurityDetection.ReadWrite.All"

# 列出所有设备组,找到目标组的ID
Get-MgDeviceManagementDeviceGroup | Select-Object Id, DisplayName

将目标组的ID赋值给变量:$targetDeviceGroupId = "你的设备组ID"

步骤2:批量更新自定义检测规则

使用以下脚本批量替换所有自定义规则的设备组:

# 导入模块(如果未自动加载)
Import-Module Microsoft.Graph.Security

# 替换为你的目标设备组ID
$targetDeviceGroupId = "YOUR-TARGET-DEVICE-GROUP-ID"

# 获取所有自定义检测规则(过滤掉系统默认规则)
$customRules = Get-MgSecurityDetectionRule -Filter "Kind eq 'Custom'"

# 循环更新每条规则
foreach ($rule in $customRules) {
    # 构建更新参数:覆盖原有设备组为目标组
    $updateParams = @{
        deviceGroups = @($targetDeviceGroupId)
    }

    try {
        Update-MgSecurityDetectionRule -DetectionRuleId $rule.Id -BodyParameter $updateParams
        Write-Host "✅ 成功更新规则:$($rule.DisplayName)" -ForegroundColor Green
    }
    catch {
        Write-Host "❌ 更新规则失败 $($rule.DisplayName):$($_.Exception.Message)" -ForegroundColor Red
    }

    # 可选:添加延迟避免触发Graph API速率限制
    Start-Sleep -Milliseconds 300
}

关键注意事项

  • 先测试再全量执行:可以在获取规则时添加-Top 5参数,先更新5条规则验证效果,比如:
    $customRules = Get-MgSecurityDetectionRule -Filter "Kind eq 'Custom'" -Top 5
    
  • 速率限制:Microsoft Graph API对请求频率有限制,500条规则建议添加300-500毫秒的延迟,避免被限流
  • 规则状态:更新设备组不会改变规则的启用/禁用状态,原有规则状态保持不变
  • 权限验证:如果执行时出现权限错误,检查账号是否拥有SecurityDetection.ReadWrite.All权限

内容的提问来源于stack exchange,提问作者Manisha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 09:01:01