使用Azure Python SDK获取订阅下Reader角色用户与应用遇过滤问题
问题:获取Azure订阅下Reader角色的用户/应用时过滤器报错
需求:使用Azure Python SDK获取指定订阅下被分配「Reader」角色的用户和应用,尝试用AuthorizationManagementClient的role_assignments.list_for_scope()方法并组合过滤器,触发不支持的查询错误。
原代码
from azure.identity import ClientSecretCredential from azure.mgmt.authorization import AuthorizationManagementClient scope = f"subscriptions/{subscription_id}" reader_role_definition_id = "/providers/Microsoft.Authorization/roleDefinitions/acdd72a7-3385-48ef-bd42-f606fba81ae7" credential = ClientSecretCredential( tenant_id=tenant_id, client_id=client_id, client_secret=client_secret ) authorization_client = AuthorizationManagementClient(credential, subscription_id) try: print("\nFetching users and applications with 'Reader' role in the subscription...") role_assignments = authorization_client.role_assignments.list_for_scope( scope=scope, filter=f"atScope() and roleDefinitionId eq '{reader_role_definition_id}'" ) print("Users or applications with Reader Role:") for assignment in role_assignments: print(f"Principal ID: {assignment.principal_id}") except Exception as e: print("Failed to fetch users or applications with 'Reader' role:", str(e))
错误信息
Fetching users and applications with 'Reader' role in the subscription... Users or applications with Reader Role: Failed to fetch users or applications with 'Reader' role: (UnsupportedQuery) 不支持过滤器'atScope() and roleDefinitionId eq '/providers/Microsoft.Authorization/roleDefinitions/acdd72a7-3385-48ef-bd42-f606fba81ae7''。支持的过滤器为'atScope()'或'principalId eq '{value}'或assignedTo('{value}')'。 Code: UnsupportedQuery Message: 不支持过滤器'atScope() and roleDefinitionId eq '/providers/Microsoft.Authorization/roleDefinitions/acdd72a7-3385-48ef-bd42-f606fba81ae7''。支持的过滤器为'atScope()'或'principalId eq '{value}'或assignedTo('{value}')'。
解决方案
Azure RBAC的list_for_scope API不支持同时组合atScope()和roleDefinitionId的过滤条件,只能先获取订阅级别的所有角色分配,再在客户端本地筛选匹配Reader角色的条目。
修改后的代码:
from azure.identity import ClientSecretCredential from azure.mgmt.authorization import AuthorizationManagementClient scope = f"subscriptions/{subscription_id}" reader_role_definition_id = "/providers/Microsoft.Authorization/roleDefinitions/acdd72a7-3385-48ef-bd42-f606fba81ae7" credential = ClientSecretCredential( tenant_id=tenant_id, client_id=client_id, client_secret=client_secret ) authorization_client = AuthorizationManagementClient(credential, subscription_id) try: print("\nFetching users and applications with 'Reader' role in the subscription...") # 先获取订阅范围内所有角色分配 role_assignments = authorization_client.role_assignments.list_for_scope( scope=scope, filter="atScope()" ) print("Users or applications with Reader Role:") # 本地筛选Reader角色的分配 reader_assignments = [a for a in role_assignments if a.role_definition_id == reader_role_definition_id] for assignment in reader_assignments: print(f"Principal ID: {assignment.principal_id}") except Exception as e: print("Failed to fetch users or applications with 'Reader' role:", str(e))
说明
- SDK返回的
role_assignments是可迭代对象,会自动处理分页,无需额外处理多页数据 - 如果订阅下角色分配数量极大,本地筛选可能会有性能影响,但这是当前API限制下的可行方案
内容的提问来源于stack exchange,提问作者James Wilton
相关产品推荐
相关产品推荐

