You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Update-MgUser在无人值守脚本中配置Entra用户认证邮箱遇阻

解决Update-MgUser更新用户认证邮箱的400错误问题

问题根源

你试的几种哈希表写法都不符合Microsoft Graph API对Authentication.EmailMethods的格式要求:

  • EmailMethods是数组类型,必须用@()包裹单个或多个对象
  • 每个邮箱认证方法对象必须指定@odata.type属性,明确类型为#microsoft.graph.emailAuthenticationMethod
  • 传递不完整的对象结构会直接触发400格式错误

正确代码示例

# 构建符合Graph要求的Authentication参数
$authenticationParams = @{
    EmailMethods = @(
        @{
            "@odata.type" = "#microsoft.graph.emailAuthenticationMethod"
            EmailAddress = "newemail@example.com"
        }
    )
}

# 执行用户更新
Update-MgUser -UserId $userId -Authentication $authenticationParams

额外注意事项

  • 确保应用已被授予UserAuthenticationMethod.ReadWrite.All应用权限(委托权限不支持无人值守脚本场景)
  • 如果用户已有邮箱认证方法,这个操作会直接替换现有列表;要是想保留原有方法,得先通过Get-MgUserAuthenticationEmailMethod获取现有方法,再合并到数组里一起传递
  • 要验证目标邮箱地址格式正确,且没被其他用户用作认证邮箱

内容的提问来源于stack exchange,提问作者dmw_code

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 15:13:16