能否通过PowerShell激活Entra ID PIM组成员身份?
激活PIM组成员身份的PowerShell/Azure CLI方法
你提到的PIM组激活属于Azure AD特权组管理范畴,和Azure RBAC角色(比如Contributor)的PIM操作分属不同模块,以下是具体实现方式:
PowerShell 实现步骤
需要使用AzureADPreview模块(正式版AzureAD模块暂不支持该操作):
- 安装并导入预览模块:
Install-Module -Name AzureADPreview -Force -AllowClobber Import-Module AzureADPreview
- 连接到Azure AD:
Connect-AzureAD
- 查询当前用户的符合条件的组分配(替换
<你的用户对象ID>):
$eligibleAssignments = Get-AzureADMSPrivilegedRoleAssignment -ProviderId "aadGroups" -Filter "subjectId eq '<你的用户对象ID>' and assignmentState eq 'Eligible'"
- 筛选目标组的分配(替换
<目标组对象ID>):
$targetGroupAssignment = $eligibleAssignments | Where-Object { $_.ResourceId -eq '<目标组对象ID>' }
- 创建激活请求(这里设置有效期为8小时,可按需调整
EndDateTime):
New-AzureADMSPrivilegedRoleAssignmentRequest -ProviderId "aadGroups" ` -RoleDefinitionId $targetGroupAssignment.RoleDefinitionId ` -ResourceId $targetGroupAssignment.ResourceId ` -SubjectId $targetGroupAssignment.SubjectId ` -Type "UserAdd" ` -AssignmentState "Active" ` -ScheduleType "Once" ` -StartDateTime (Get-Date) ` -EndDateTime (Get-Date).AddHours(8) ` -Reason "业务操作需要"
Azure CLI 实现步骤
使用Azure AD特权身份管理相关命令:
- 登录Azure CLI:
az login
- 查询符合条件的组分配(替换
<你的用户对象ID>):
az ad privileged-role-assignment list --provider aad-groups --filter "subjectId eq '<你的用户对象ID>' and assignmentState eq 'Eligible'"
- 创建激活请求(替换占位符,有效期设为8小时):
az ad privileged-role-assignment-request create --provider aad-groups \ --role-definition-id <组角色定义ID(成员角色ID为62e90394-69f5-4237-9190-012177145e10,所有者角色ID为88d8e3e3-8f55-4a1e-953a-9b9898b8876b)> \ --resource-id <目标组对象ID> \ --subject-id <你的用户对象ID> \ --type UserAdd \ --assignment-state Active \ --schedule-type Once \ --start-datetime "$(date +%Y-%m-%dT%H:%M:%SZ)" \ --end-datetime "$(date -d '+8 hours' +%Y-%m-%dT%H:%M:%SZ)" \ --reason "业务操作需要"
注意事项
- PowerShell必须使用
AzureADPreview模块,若已安装正式版AzureAD模块,需用-AllowClobber参数覆盖 ProviderId参数是核心区分项:aadGroups(PowerShell)/aad-groups(Azure CLI)对应Azure AD组的PIM操作,而Azure RBAC角色用azureResources- 可根据实际需求调整激活的有效期、理由等参数
内容的提问来源于stack exchange,提问作者pgbfnf
相关产品推荐
相关产品推荐

