You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否通过PowerShell激活Entra ID PIM组成员身份?

激活PIM组成员身份的PowerShell/Azure CLI方法

你提到的PIM组激活属于Azure AD特权组管理范畴,和Azure RBAC角色(比如Contributor)的PIM操作分属不同模块,以下是具体实现方式:

PowerShell 实现步骤

需要使用AzureADPreview模块(正式版AzureAD模块暂不支持该操作):

  1. 安装并导入预览模块:
Install-Module -Name AzureADPreview -Force -AllowClobber
Import-Module AzureADPreview
  1. 连接到Azure AD:
Connect-AzureAD
  1. 查询当前用户的符合条件的组分配(替换<你的用户对象ID>):
$eligibleAssignments = Get-AzureADMSPrivilegedRoleAssignment -ProviderId "aadGroups" -Filter "subjectId eq '<你的用户对象ID>' and assignmentState eq 'Eligible'"
  1. 筛选目标组的分配(替换<目标组对象ID>):
$targetGroupAssignment = $eligibleAssignments | Where-Object { $_.ResourceId -eq '<目标组对象ID>' }
  1. 创建激活请求(这里设置有效期为8小时,可按需调整EndDateTime):
New-AzureADMSPrivilegedRoleAssignmentRequest -ProviderId "aadGroups" `
    -RoleDefinitionId $targetGroupAssignment.RoleDefinitionId `
    -ResourceId $targetGroupAssignment.ResourceId `
    -SubjectId $targetGroupAssignment.SubjectId `
    -Type "UserAdd" `
    -AssignmentState "Active" `
    -ScheduleType "Once" `
    -StartDateTime (Get-Date) `
    -EndDateTime (Get-Date).AddHours(8) `
    -Reason "业务操作需要"

Azure CLI 实现步骤

使用Azure AD特权身份管理相关命令:

  1. 登录Azure CLI:
az login
  1. 查询符合条件的组分配(替换<你的用户对象ID>):
az ad privileged-role-assignment list --provider aad-groups --filter "subjectId eq '<你的用户对象ID>' and assignmentState eq 'Eligible'"
  1. 创建激活请求(替换占位符,有效期设为8小时):
az ad privileged-role-assignment-request create --provider aad-groups \
    --role-definition-id <组角色定义ID(成员角色ID为62e90394-69f5-4237-9190-012177145e10,所有者角色ID为88d8e3e3-8f55-4a1e-953a-9b9898b8876b)> \
    --resource-id <目标组对象ID> \
    --subject-id <你的用户对象ID> \
    --type UserAdd \
    --assignment-state Active \
    --schedule-type Once \
    --start-datetime "$(date +%Y-%m-%dT%H:%M:%SZ)" \
    --end-datetime "$(date -d '+8 hours' +%Y-%m-%dT%H:%M:%SZ)" \
    --reason "业务操作需要"

注意事项

  • PowerShell必须使用AzureADPreview模块,若已安装正式版AzureAD模块,需用-AllowClobber参数覆盖
  • ProviderId参数是核心区分项:aadGroups(PowerShell)/aad-groups(Azure CLI)对应Azure AD组的PIM操作,而Azure RBAC角色用azureResources
  • 可根据实际需求调整激活的有效期、理由等参数

内容的提问来源于stack exchange,提问作者pgbfnf

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 18:15:10