使用PowerShell脚本通过Graph API添加Intune设备到安全组时遇404错误
问题排查:PowerShell脚本添加Intune设备到Entra ID安全组时404错误
我用PowerShell脚本检测注册表项后,将Intune设备加入Entra ID安全组。脚本大部分流程正常:注册表检测输出符合预期,能成功获取设备Object ID,但执行添加到安全组步骤时失败,抛出Error 404 Not Found。用Fiddler抓包看到错误信息:
{"error":{"code":"Request_ResourceNotFound","message":"Resource '<我的设备ID>' does not exist or one of its queried reference-property objects are not present."}}
该设备ID在Intune中能正常查到,试过相关建议仍未解决,求排查。完整脚本如下:
# 定义变量 $TenantID = "*我的租户ID*" $ClientID = "*注册应用的客户端ID*" $ClientSecret = "*应用密钥*" $SecurityGroupID = "*要添加设备的安全组ID*" $RegistryPath = "*HKLM:\SOFTWARE\...*" $RegistryValue = "*用于检测的测试值*" # 获取Microsoft Graph访问令牌的函数 function Get-GraphToken { $body = @{ grant_type = "client_credentials" client_id = $ClientID client_secret = $ClientSecret scope = "https://graph.microsoft.com/.default" } $response = Invoke-RestMethod -Method Post -Uri "https://login.microsoftonline.com/$TenantID/oauth2/v2.0/token" -ContentType "application/x-www-form-urlencoded" -Body $body return $response.access_token } # 获取Intune设备ID的函数 function Get-IntuneDeviceID { param ( [string]$DeviceName ) $token = Get-GraphToken $headers = @{ Authorization = "Bearer $token" } $url = "https://graph.microsoft.com/v1.0/devicemanagement/managedDevices?`$filter=deviceName eq '$DeviceName'" $response = Invoke-RestMethod -Method Get -Uri $url -Headers $headers -ContentType "application/json" if ($response.value.Count -gt 0) { return $response.value[0].id } else { Write-Host "Intune中未找到设备。" -ForegroundColor Red return $null } } # 将设备添加到安全组的函数 function Add-DeviceToGroup { param ( [string]$DeviceID ) $token = Get-GraphToken $headers = @{ Authorization = "Bearer $token" ; "Content-Type" = "application/json" } $body = @{ "@odata.id" = "https://graph.microsoft.com/v1.0/devices/$DeviceID" } | ConvertTo-Json -Depth 2 $url = "https://graph.microsoft.com/v1.0/groups/$SecurityGroupID/members/`$ref" $response = Invoke-RestMethod -Method Post -Uri $url -Headers $headers -Body $body Write-Host "设备已成功添加到安全组。" -ForegroundColor Green } # 检查注册表项是否存在 if (Test-Path $RegistryPath) { $regValue = Get-ItemProperty -Path $RegistryPath -Name $RegistryValue -ErrorAction SilentlyContinue if ($regValue -ne $null) { Write-Host "找到注册表项。开始执行Intune操作。" -ForegroundColor Yellow $DeviceName = $env:COMPUTERNAME $DeviceID = Get-IntuneDeviceID -DeviceName $DeviceName if ($DeviceID) { Add-DeviceToGroup -DeviceID $DeviceID } } else { Write-Host "注册表项存在,但未找到对应值。" -ForegroundColor Red } } else { Write-Host "未找到注册表项。未执行任何操作。" -ForegroundColor Red }
问题根源与解决方案
1. 核心问题:设备ID不匹配
你当前脚本中Get-IntuneDeviceID获取的是Intune管理设备ID(来自devicemanagement/managedDevices的id字段),但添加到Entra安全组需要的是Entra ID设备对象ID(来自devices的id字段)——这两个是完全不同的标识符,导致Graph API找不到对应资源,抛出404错误。
2. 修正脚本步骤
步骤1:修改设备ID获取函数,获取正确的Entra设备ID
替换原Get-IntuneDeviceID函数,先获取Intune设备关联的deviceId,再通过该值查询Entra的设备对象ID:
function Get-EntraDeviceID { param ( [string]$DeviceName ) $token = Get-GraphToken $headers = @{ Authorization = "Bearer $token" } # 获取Intune设备的deviceId(关联Entra设备的关键值) $intuneUrl = "https://graph.microsoft.com/v1.0/devicemanagement/managedDevices?`$filter=deviceName eq '$DeviceName'&`$select=deviceId" $intuneResponse = Invoke-RestMethod -Method Get -Uri $intuneUrl -Headers $headers -ContentType "application/json" if ($intuneResponse.value.Count -eq 0) { Write-Host "Intune中未找到设备。" -ForegroundColor Red return $null } $deviceId = $intuneResponse.value[0].deviceId # 通过deviceId查询Entra设备的对象ID $entraUrl = "https://graph.microsoft.com/v1.0/devices?`$filter=deviceId eq '$deviceId'&`$select=id" $entraResponse = Invoke-RestMethod -Method Get -Uri $entraUrl -Headers $headers -ContentType "application/json" if ($entraResponse.value.Count -gt 0) { return $entraResponse.value[0].id } else { Write-Host "Entra ID中未找到对应设备。" -ForegroundColor Red return $null } }
步骤2:更新主流程调用
将原脚本中的Get-IntuneDeviceID替换为Get-EntraDeviceID:
if ($regValue -ne $null) { Write-Host "找到注册表项。开始执行Intune操作。" -ForegroundColor Yellow $DeviceName = $env:COMPUTERNAME $DeviceID = Get-EntraDeviceID -DeviceName $DeviceName if ($DeviceID) { Add-DeviceToGroup -DeviceID $DeviceID } }
步骤3:确认应用权限
确保你的Azure AD应用注册已添加以下应用权限,并完成管理员同意:
Device.Read.All:读取所有设备信息GroupMember.ReadWrite.All:读写组成员
3. 额外验证建议
- 手动调用Graph API验证:用
GET https://graph.microsoft.com/v1.0/devices?$filter=deviceId eq '<Intune设备的deviceId>'`确认能返回Entra设备对象 - 检查安全组类型:确保目标组是安全组,而非Microsoft 365组(安全组适配性更稳定)
内容的提问来源于stack exchange,提问作者Gacrux
相关产品推荐
相关产品推荐

