如何批量修改Microsoft Defender中500+自定义检测规则的设备组?
批量更新Microsoft Defender自定义检测规则的设备组方案
完全可以通过Microsoft Graph API + PowerShell实现批量修改,手动处理500+条规则效率极低,自动化是最优解。以下是具体实现步骤和脚本:
前置准备
- 权限要求:需要拥有
Security Administrator、Global Administrator角色,或自定义权限包含SecurityDetection.ReadWrite.All权限 - 安装模块:确保已安装Microsoft Graph PowerShell Security模块:
Install-Module Microsoft.Graph.Security -Force -AllowClobber
步骤1:获取目标设备组ID
先查询所有设备组,找到你要设置的新设备组ID:
# 连接到Microsoft Graph Connect-MgGraph -Scopes "SecurityDetection.ReadWrite.All" # 列出所有设备组,找到目标组的ID Get-MgDeviceManagementDeviceGroup | Select-Object Id, DisplayName
将目标组的ID赋值给变量:$targetDeviceGroupId = "你的设备组ID"
步骤2:批量更新自定义检测规则
使用以下脚本批量替换所有自定义规则的设备组:
# 导入模块(如果未自动加载) Import-Module Microsoft.Graph.Security # 替换为你的目标设备组ID $targetDeviceGroupId = "YOUR-TARGET-DEVICE-GROUP-ID" # 获取所有自定义检测规则(过滤掉系统默认规则) $customRules = Get-MgSecurityDetectionRule -Filter "Kind eq 'Custom'" # 循环更新每条规则 foreach ($rule in $customRules) { # 构建更新参数:覆盖原有设备组为目标组 $updateParams = @{ deviceGroups = @($targetDeviceGroupId) } try { Update-MgSecurityDetectionRule -DetectionRuleId $rule.Id -BodyParameter $updateParams Write-Host "✅ 成功更新规则:$($rule.DisplayName)" -ForegroundColor Green } catch { Write-Host "❌ 更新规则失败 $($rule.DisplayName):$($_.Exception.Message)" -ForegroundColor Red } # 可选:添加延迟避免触发Graph API速率限制 Start-Sleep -Milliseconds 300 }
关键注意事项
- 先测试再全量执行:可以在获取规则时添加
-Top 5参数,先更新5条规则验证效果,比如:$customRules = Get-MgSecurityDetectionRule -Filter "Kind eq 'Custom'" -Top 5 - 速率限制:Microsoft Graph API对请求频率有限制,500条规则建议添加300-500毫秒的延迟,避免被限流
- 规则状态:更新设备组不会改变规则的启用/禁用状态,原有规则状态保持不变
- 权限验证:如果执行时出现权限错误,检查账号是否拥有
SecurityDetection.ReadWrite.All权限
内容的提问来源于stack exchange,提问作者Manisha
相关产品推荐
相关产品推荐

