如何获取AzureAD指定组用户激活已分配角色的操作记录?
提取指定群组用户激活角色的操作人及时间信息
可以通过Microsoft Graph API或PowerShell实现需求,以下是具体方案:
一、Microsoft Graph API 方案
1. 普通角色分配审计(非PIM激活)
如果是用户被添加到与群组关联的角色中,调用**auditLogs/directoryAudits**端点,筛选Add member to role事件并指定目标群组:
GET https://graph.microsoft.com/v1.0/auditLogs/directoryAudits $filter=activityDisplayName eq 'Add member to role' and targetResources/any(tr: tr/id eq '{你的群组ID}')
响应中关键字段:
activityDateTime:操作时间initiatedBy.user.displayName/initiatedBy.user.userPrincipalName:操作人信息targetResources:包含角色、用户、群组的详细信息
2. PIM角色激活审计
如果是用户通过特权身份管理(PIM)激活角色,调用**privilegedAccess/azureResources/roleAssignmentScheduleRequests**端点,需先获取群组成员ID再筛选:
GET https://graph.microsoft.com/v1.0/privilegedAccess/azureResources/roleAssignmentScheduleRequests $filter=requestType eq 'SelfActivate' and principalId in ('{成员ID1}','{成员ID2}')
(可先调用groups/{群组ID}/members获取所有成员ID)
二、PowerShell 方案
1. 使用Microsoft Graph PowerShell模块(推荐)
先完成模块安装与授权:
Install-Module Microsoft.Graph -Force Connect-MgGraph -Scopes AuditLog.Read.All, PrivilegedAccess.Read.AzureResources
普通角色分配查询
$groupId = "你的群组ID" Get-MgAuditLogDirectoryAudit -Filter "activityDisplayName eq 'Add member to role' and targetResources/any(tr: tr/id eq '$groupId')" | Select-Object ActivityDateTime, @{Name='操作人'; Expression={$_.InitiatedBy.User.DisplayName}}, @{Name='操作人UPN'; Expression={$_.InitiatedBy.User.UserPrincipalName}}, TargetResources
PIM角色激活查询
$groupId = "你的群组ID" # 获取群组所有成员ID $groupMembers = Get-MgGroupMember -GroupId $groupId -All $true | Select-Object -ExpandProperty Id # 查询成员的角色激活请求 Get-MgPrivilegedAccessAzureResourceRoleAssignmentScheduleRequest -Filter "requestType eq 'SelfActivate' and principalId in ('$($groupMembers -join "','")')" | Select-Object CreatedDateTime, @{Name='操作人'; Expression={$_.CreatedBy.User.DisplayName}}, @{Name='角色名称'; Expression={$_.RoleDefinition.DisplayName}}
2. 修复AzureAD模块的使用问题
你之前调用Get-AzureADAuditDirectoryLogs失败,大概率是权限不足或筛选条件错误。确保账号拥有AuditLog.Read.All权限后,尝试以下命令:
Connect-AzureAD $groupId = "你的群组ID" Get-AzureADAuditDirectoryLogs -Filter "ActivityDisplayName eq 'Add member to role' and TargetResources/Any(tr: tr/Id eq '$groupId')" | Select-Object ActivityDateTime, InitiatedBy, TargetResources
注意事项
- 权限:必须确保执行账号拥有
AuditLog.Read.All(审计日志)和PrivilegedAccess.Read.AzureResources(PIM日志)的权限 - 事件区分:普通角色分配和PIM角色激活是不同事件,需根据实际场景选择对应查询方式
- 时间范围:默认查询最近30天的日志,如需更早数据需指定
-Filter中的时间范围
内容的提问来源于stack exchange,提问作者cheerrycherry
相关产品推荐
相关产品推荐

