You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决Microsoft Entra ID PowerShell中的‘Invalid operands -eq’错误

问题定位与解决

错误原因

你的membershipRule语法不符合Microsoft Entra ID动态规则要求:当比较字符串类型属性(比如user.country)时,右侧的字符串值必须用引号包裹。当前代码中user.country -eq $Code里的$Code是字符串变量,但未加引号,导致Graph规则引擎将其识别为属性名而非具体值,触发了-eq操作数类型不匹配的错误。

解决方法

修改membershipRule的写法,给$Code加上单引号(或双引号),确保规则引擎将其视为字符串值。

修改后的代码

foreach ($AU in $AUList) {
    $Code = $AU.CountryCode
    $Name = $AU.CountryName
    $params = @{
        displayName = "$Code" + "_Users"
        description = "A dynamic administrative unit for " + "$Name"
        membershipType = "Dynamic"
        # 给$Code添加单引号,确保字符串值被正确识别
        membershipRule = "(user.dirSyncEnabled -eq True) and (user.country -eq '$Code')"
        membershipRuleProcessingState = "On"
        visibility = "HiddenMembership"
    }
    $adminUnitObj = New-MgDirectoryAdministrativeUnit -BodyParameter $params
}

补充说明

如果$Code本身包含特殊字符(比如单引号),可以改用双引号包裹并转义,或者使用PowerShell的字符串格式化来避免冲突:

# 双引号转义写法
membershipRule = "(user.dirSyncEnabled -eq True) and (user.country -eq ""$Code"")"
# 字符串格式化写法
membershipRule = "(user.dirSyncEnabled -eq True) and (user.country -eq '{0}')" -f $Code

内容的提问来源于stack exchange,提问作者BPengu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 16:52:08