You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用PowerShell脚本通过Graph API添加Intune设备到安全组时遇404错误

问题排查:PowerShell脚本添加Intune设备到Entra ID安全组时404错误

我用PowerShell脚本检测注册表项后,将Intune设备加入Entra ID安全组。脚本大部分流程正常:注册表检测输出符合预期,能成功获取设备Object ID,但执行添加到安全组步骤时失败,抛出Error 404 Not Found。用Fiddler抓包看到错误信息:

{"error":{"code":"Request_ResourceNotFound","message":"Resource '<我的设备ID>' does not exist or one of its queried reference-property objects are not present."}}

该设备ID在Intune中能正常查到,试过相关建议仍未解决,求排查。完整脚本如下:

# 定义变量
$TenantID = "*我的租户ID*"
$ClientID = "*注册应用的客户端ID*"
$ClientSecret = "*应用密钥*"
$SecurityGroupID = "*要添加设备的安全组ID*"
$RegistryPath = "*HKLM:\SOFTWARE\...*"
$RegistryValue = "*用于检测的测试值*"

# 获取Microsoft Graph访问令牌的函数
function Get-GraphToken {
    $body = @{
        grant_type    = "client_credentials"
        client_id     = $ClientID
        client_secret = $ClientSecret
        scope         = "https://graph.microsoft.com/.default"
    }
    $response = Invoke-RestMethod -Method Post -Uri "https://login.microsoftonline.com/$TenantID/oauth2/v2.0/token" -ContentType "application/x-www-form-urlencoded" -Body $body
    return $response.access_token
}

# 获取Intune设备ID的函数
function Get-IntuneDeviceID {
    param (
        [string]$DeviceName
    )
    $token = Get-GraphToken
    $headers = @{ Authorization = "Bearer $token" }

    $url = "https://graph.microsoft.com/v1.0/devicemanagement/managedDevices?`$filter=deviceName eq '$DeviceName'"
    $response = Invoke-RestMethod -Method Get -Uri $url -Headers $headers -ContentType "application/json"

    if ($response.value.Count -gt 0) {
        return $response.value[0].id
    } else {
        Write-Host "Intune中未找到设备。" -ForegroundColor Red
        return $null
    }
}

# 将设备添加到安全组的函数
function Add-DeviceToGroup {
    param (
        [string]$DeviceID
    )
    $token = Get-GraphToken
    $headers = @{ Authorization = "Bearer $token" ; "Content-Type" = "application/json" }
    
    $body = @{
        "@odata.id" = "https://graph.microsoft.com/v1.0/devices/$DeviceID"
    } | ConvertTo-Json -Depth 2

    $url = "https://graph.microsoft.com/v1.0/groups/$SecurityGroupID/members/`$ref"
    $response = Invoke-RestMethod -Method Post -Uri $url -Headers $headers -Body $body

    Write-Host "设备已成功添加到安全组。" -ForegroundColor Green
}

# 检查注册表项是否存在
if (Test-Path $RegistryPath) {
    $regValue = Get-ItemProperty -Path $RegistryPath -Name $RegistryValue -ErrorAction SilentlyContinue
    if ($regValue -ne $null) {
        Write-Host "找到注册表项。开始执行Intune操作。" -ForegroundColor Yellow
        $DeviceName = $env:COMPUTERNAME
        $DeviceID = Get-IntuneDeviceID -DeviceName $DeviceName

        if ($DeviceID) {
            Add-DeviceToGroup -DeviceID $DeviceID
        }
    } else {
        Write-Host "注册表项存在,但未找到对应值。" -ForegroundColor Red
    }
} else {
    Write-Host "未找到注册表项。未执行任何操作。" -ForegroundColor Red
}

问题根源与解决方案

1. 核心问题:设备ID不匹配

你当前脚本中Get-IntuneDeviceID获取的是Intune管理设备ID(来自devicemanagement/managedDevices的id字段),但添加到Entra安全组需要的是Entra ID设备对象ID(来自devices的id字段)——这两个是完全不同的标识符,导致Graph API找不到对应资源,抛出404错误。

2. 修正脚本步骤

步骤1:修改设备ID获取函数,获取正确的Entra设备ID

替换原Get-IntuneDeviceID函数,先获取Intune设备关联的deviceId,再通过该值查询Entra的设备对象ID:

function Get-EntraDeviceID {
    param (
        [string]$DeviceName
    )
    $token = Get-GraphToken
    $headers = @{ Authorization = "Bearer $token" }

    # 获取Intune设备的deviceId(关联Entra设备的关键值)
    $intuneUrl = "https://graph.microsoft.com/v1.0/devicemanagement/managedDevices?`$filter=deviceName eq '$DeviceName'&`$select=deviceId"
    $intuneResponse = Invoke-RestMethod -Method Get -Uri $intuneUrl -Headers $headers -ContentType "application/json"

    if ($intuneResponse.value.Count -eq 0) {
        Write-Host "Intune中未找到设备。" -ForegroundColor Red
        return $null
    }

    $deviceId = $intuneResponse.value[0].deviceId
    # 通过deviceId查询Entra设备的对象ID
    $entraUrl = "https://graph.microsoft.com/v1.0/devices?`$filter=deviceId eq '$deviceId'&`$select=id"
    $entraResponse = Invoke-RestMethod -Method Get -Uri $entraUrl -Headers $headers -ContentType "application/json"

    if ($entraResponse.value.Count -gt 0) {
        return $entraResponse.value[0].id
    } else {
        Write-Host "Entra ID中未找到对应设备。" -ForegroundColor Red
        return $null
    }
}

步骤2:更新主流程调用

将原脚本中的Get-IntuneDeviceID替换为Get-EntraDeviceID:

if ($regValue -ne $null) {
    Write-Host "找到注册表项。开始执行Intune操作。" -ForegroundColor Yellow
    $DeviceName = $env:COMPUTERNAME
    $DeviceID = Get-EntraDeviceID -DeviceName $DeviceName

    if ($DeviceID) {
        Add-DeviceToGroup -DeviceID $DeviceID
    }
}

步骤3:确认应用权限

确保你的Azure AD应用注册已添加以下应用权限,并完成管理员同意:

  • Device.Read.All:读取所有设备信息
  • GroupMember.ReadWrite.All:读写组成员

3. 额外验证建议

  • 手动调用Graph API验证:用GET https://graph.microsoft.com/v1.0/devices?$filter=deviceId eq '<Intune设备的deviceId>'`确认能返回Entra设备对象
  • 检查安全组类型:确保目标组是安全组,而非Microsoft 365组(安全组适配性更稳定)

内容的提问来源于stack exchange,提问作者Gacrux

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 08:29:52