You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure PIM权限身份管理脚本编写故障排查请求

Azure PIM自动化部署脚本问题诊断与修正

核心问题梳理

  1. 废弃模块依赖:原脚本使用的AzureAD模块已被官方弃用,当前PIM操作需使用Microsoft.Graph模块
  2. ProviderId参数错误:针对Azure资源组的PIM管理,ProviderId应为azureResources,而非用于Entra ID角色的aadRoles
  3. PIM配置逻辑错误:原脚本先创建永久角色分配,再尝试修改PIM设置,正确流程应先启用资源组的PIM功能,再创建合格(Eligible)角色分配
  4. B2C功能兼容性:PIM不支持Microsoft Entra B2C租户,若你的测试环境为B2C租户,PIM功能本身无法正常工作

修正后的完整脚本

# 安装并导入Microsoft.Graph模块(若未安装)
if (-not (Get-Module -ListAvailable -Name Microsoft.Graph)) {
    Install-Module -Name Microsoft.Graph -Force -AllowClobber
}
Import-Module Microsoft.Graph.Identity.Governance

# 登录Azure并设置订阅上下文
Connect-AzAccount
$subscriptionId = "xxx"
$resourceGroupName = "my-rg"
$azureAdGroupName = "RG_OWNER_GROUP"
Set-AzContext -SubscriptionId $subscriptionId

# 获取资源组
$resourceGroup = Get-AzResourceGroup -Name $resourceGroupName
if (-not $resourceGroup) {
    Write-Host "资源组 '$resourceGroupName' 不存在。"
    exit
}

# 登录Microsoft Graph(需Privileged Role Administrator权限)
Connect-MgGraph -Scopes "PrivilegedAccess.ReadWrite.AzureResources","Directory.Read.All","RoleAssignmentSchedule.ReadWrite.Directory"

# 获取Azure AD组
$azureAdGroup = Get-MgGroup -Filter "displayName eq '$azureAdGroupName'"
if (-not $azureAdGroup) {
    Write-Host "Azure AD组 '$azureAdGroupName' 不存在。"
    exit
}

# 资源组ID与角色定义
$resourceGroupId = "/subscriptions/$subscriptionId/resourceGroups/$resourceGroupName"
$roleDefinition = Get-AzRoleDefinition -Name "Owner"

# 启用资源组的PIM功能(若未启用)
try {
    $existingSettings = Get-MgPrivilegedAccessSetting -ProviderId "azureResources" -ResourceId $resourceGroupId
} catch {
    # 若未启用,创建默认设置
    New-MgPrivilegedAccessSetting -ProviderId "azureResources" -ResourceId $resourceGroupId -BodyParameter @{
        RoleSettings = @(
            @{
                RoleDefinitionId = $roleDefinition.Id
                DisplayName = $roleDefinition.Name
                IsDefault = $true
                RoleMemberSettings = @{
                    PermanentAssignment = $false
                    EligibleAssignment = $true
                }
                RoleEligibilityScheduleSettings = @{
                    ExpirationDuration = "P365D" # 有效期1年
                }
            }
        )
    }
    Write-Host "已启用资源组 '$resourceGroupName' 的PIM功能。"
}

# 创建合格的PIM角色分配
New-MgRoleEligibilityScheduleRequest -BodyParameter @{
    Action = "AdminAssign"
    Justification = "自动化PIM角色分配"
    RoleDefinitionId = $roleDefinition.Id
    DirectoryScopeId = $resourceGroupId
    PrincipalId = $azureAdGroup.Id
    ScheduleInfo = @{
        StartDateTime = (Get-Date).ToString("yyyy-MM-ddTHH:mm:ssZ")
        Expiration = @{
            Type = "AfterDuration"
            Duration = "P365D"
        }
    }
}

Write-Host "PIM已成功配置:资源组 '$resourceGroupName',Azure AD组 '$azureAdGroupName' 获得Owner角色的合格分配。"

关键修正说明

  • 模块替换:用Microsoft.Graph.Identity.Governance模块替代废弃的AzureAD模块,支持最新的PIM API
  • ProviderId修正:使用azureResources作为资源组级PIM的ProviderId,aadRoles仅用于Entra ID全局/目录角色
  • PIM启用流程:先检查资源组是否已启用PIM,未启用则创建默认角色设置
  • 角色分配类型:直接创建合格(Eligible)角色分配,无需先创建永久分配再修改
  • 权限要求:运行脚本的账号需具备Privileged Role Administrator或Global Administrator权限,以及资源组的Owner权限

内容的提问来源于stack exchange,提问作者learner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 16:20:12