You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何获取AzureAD指定组用户激活已分配角色的操作记录?

提取指定群组用户激活角色的操作人及时间信息

可以通过Microsoft Graph API或PowerShell实现需求,以下是具体方案:

一、Microsoft Graph API 方案

1. 普通角色分配审计(非PIM激活)

如果是用户被添加到与群组关联的角色中,调用**auditLogs/directoryAudits**端点,筛选Add member to role事件并指定目标群组:

GET https://graph.microsoft.com/v1.0/auditLogs/directoryAudits
$filter=activityDisplayName eq 'Add member to role' and targetResources/any(tr: tr/id eq '{你的群组ID}')

响应中关键字段:

  • activityDateTime:操作时间
  • initiatedBy.user.displayName/initiatedBy.user.userPrincipalName:操作人信息
  • targetResources:包含角色、用户、群组的详细信息

2. PIM角色激活审计

如果是用户通过特权身份管理(PIM)激活角色,调用**privilegedAccess/azureResources/roleAssignmentScheduleRequests**端点,需先获取群组成员ID再筛选:

GET https://graph.microsoft.com/v1.0/privilegedAccess/azureResources/roleAssignmentScheduleRequests
$filter=requestType eq 'SelfActivate' and principalId in ('{成员ID1}','{成员ID2}')

(可先调用groups/{群组ID}/members获取所有成员ID)

二、PowerShell 方案

1. 使用Microsoft Graph PowerShell模块(推荐)

先完成模块安装与授权:

Install-Module Microsoft.Graph -Force
Connect-MgGraph -Scopes AuditLog.Read.All, PrivilegedAccess.Read.AzureResources

普通角色分配查询

$groupId = "你的群组ID"
Get-MgAuditLogDirectoryAudit -Filter "activityDisplayName eq 'Add member to role' and targetResources/any(tr: tr/id eq '$groupId')" | 
  Select-Object ActivityDateTime, 
                @{Name='操作人'; Expression={$_.InitiatedBy.User.DisplayName}},
                @{Name='操作人UPN'; Expression={$_.InitiatedBy.User.UserPrincipalName}},
                TargetResources

PIM角色激活查询

$groupId = "你的群组ID"
# 获取群组所有成员ID
$groupMembers = Get-MgGroupMember -GroupId $groupId -All $true | Select-Object -ExpandProperty Id
# 查询成员的角色激活请求
Get-MgPrivilegedAccessAzureResourceRoleAssignmentScheduleRequest -Filter "requestType eq 'SelfActivate' and principalId in ('$($groupMembers -join "','")')" |
  Select-Object CreatedDateTime,
                @{Name='操作人'; Expression={$_.CreatedBy.User.DisplayName}},
                @{Name='角色名称'; Expression={$_.RoleDefinition.DisplayName}}

2. 修复AzureAD模块的使用问题

你之前调用Get-AzureADAuditDirectoryLogs失败,大概率是权限不足或筛选条件错误。确保账号拥有AuditLog.Read.All权限后,尝试以下命令:

Connect-AzureAD
$groupId = "你的群组ID"
Get-AzureADAuditDirectoryLogs -Filter "ActivityDisplayName eq 'Add member to role' and TargetResources/Any(tr: tr/Id eq '$groupId')" |
  Select-Object ActivityDateTime, InitiatedBy, TargetResources

注意事项

  • 权限:必须确保执行账号拥有AuditLog.Read.All(审计日志)和PrivilegedAccess.Read.AzureResources(PIM日志)的权限
  • 事件区分:普通角色分配和PIM角色激活是不同事件,需根据实际场景选择对应查询方式
  • 时间范围:默认查询最近30天的日志,如需更早数据需指定-Filter中的时间范围

内容的提问来源于stack exchange,提问作者cheerrycherry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 22:31:21