You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Azure Python SDK获取订阅下Reader角色用户与应用遇过滤问题

问题:获取Azure订阅下Reader角色的用户/应用时过滤器报错

需求:使用Azure Python SDK获取指定订阅下被分配「Reader」角色的用户和应用,尝试用AuthorizationManagementClient的role_assignments.list_for_scope()方法并组合过滤器,触发不支持的查询错误。

原代码

from azure.identity import ClientSecretCredential
from azure.mgmt.authorization import AuthorizationManagementClient

scope = f"subscriptions/{subscription_id}"
reader_role_definition_id = "/providers/Microsoft.Authorization/roleDefinitions/acdd72a7-3385-48ef-bd42-f606fba81ae7"

credential = ClientSecretCredential(
    tenant_id=tenant_id,
    client_id=client_id,
    client_secret=client_secret
)
authorization_client = AuthorizationManagementClient(credential, subscription_id)

try:
    print("\nFetching users and applications with 'Reader' role in the subscription...")
    role_assignments = authorization_client.role_assignments.list_for_scope(
        scope=scope,
        filter=f"atScope() and roleDefinitionId eq '{reader_role_definition_id}'"
    )

    print("Users or applications with Reader Role:")
    for assignment in role_assignments:
        print(f"Principal ID: {assignment.principal_id}")
except Exception as e:
    print("Failed to fetch users or applications with 'Reader' role:", str(e))

错误信息

Fetching users and applications with 'Reader' role in the subscription...
Users or applications with Reader Role:
Failed to fetch users or applications with 'Reader' role: (UnsupportedQuery) 不支持过滤器'atScope() and roleDefinitionId eq '/providers/Microsoft.Authorization/roleDefinitions/acdd72a7-3385-48ef-bd42-f606fba81ae7''。支持的过滤器为'atScope()'或'principalId eq '{value}'或assignedTo('{value}')'。
Code: UnsupportedQuery
Message: 不支持过滤器'atScope() and roleDefinitionId eq '/providers/Microsoft.Authorization/roleDefinitions/acdd72a7-3385-48ef-bd42-f606fba81ae7''。支持的过滤器为'atScope()'或'principalId eq '{value}'或assignedTo('{value}')'。

解决方案

Azure RBAC的list_for_scope API不支持同时组合atScope()和roleDefinitionId的过滤条件,只能先获取订阅级别的所有角色分配,再在客户端本地筛选匹配Reader角色的条目。

修改后的代码:

from azure.identity import ClientSecretCredential
from azure.mgmt.authorization import AuthorizationManagementClient

scope = f"subscriptions/{subscription_id}"
reader_role_definition_id = "/providers/Microsoft.Authorization/roleDefinitions/acdd72a7-3385-48ef-bd42-f606fba81ae7"

credential = ClientSecretCredential(
    tenant_id=tenant_id,
    client_id=client_id,
    client_secret=client_secret
)
authorization_client = AuthorizationManagementClient(credential, subscription_id)

try:
    print("\nFetching users and applications with 'Reader' role in the subscription...")
    # 先获取订阅范围内所有角色分配
    role_assignments = authorization_client.role_assignments.list_for_scope(
        scope=scope,
        filter="atScope()"
    )

    print("Users or applications with Reader Role:")
    # 本地筛选Reader角色的分配
    reader_assignments = [a for a in role_assignments if a.role_definition_id == reader_role_definition_id]
    for assignment in reader_assignments:
        print(f"Principal ID: {assignment.principal_id}")
except Exception as e:
    print("Failed to fetch users or applications with 'Reader' role:", str(e))

说明

  • SDK返回的role_assignments是可迭代对象,会自动处理分页,无需额外处理多页数据
  • 如果订阅下角色分配数量极大,本地筛选可能会有性能影响,但这是当前API限制下的可行方案

内容的提问来源于stack exchange,提问作者James Wilton

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 14:53:22