You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何获取Azure AD中组的合格角色分配(而非仅活动分配)

解决方案

核心原因

Get-MgRoleManagementDirectoryRoleAssignment仅返回活动角色分配(即已激活的直接角色分配),而Azure AD的「合格分配」属于角色资格调度范畴,需要使用专门的Graph PowerShell命令获取。

权限准备

确保执行命令的账号/应用已分配以下权限之一:

  • RoleManagement.Read.Directory
  • Directory.Read.All
  • RoleManagement.ReadWrite.Directory(如需修改操作)

修改后的完整代码

foreach($group in $groups){
    $objectId = $group.ObjectId
    
    # 获取活动角色分配
    $activeAssignments = Get-MgRoleManagementDirectoryRoleAssignment -Filter "PrincipalId eq '$objectId'"
    # 获取合格角色分配(角色资格)
    $eligibleAssignments = Get-MgRoleManagementDirectoryRoleEligibilitySchedule -Filter "principalId eq '$objectId'"

    # 输出活动分配信息
    foreach($assignment in $activeAssignments){
        $roleDefinition = Get-MgRoleManagementDirectoryRoleDefinition -UnifiedRoleDefinitionId $assignment.RoleDefinitionId
        Write-Output "Group Name: $($group.Name), 分配类型: 活动, 角色名称: $($roleDefinition.DisplayName)"
    }

    # 输出合格分配信息
    foreach($eligibility in $eligibleAssignments){
        $roleDefinition = Get-MgRoleManagementDirectoryRoleDefinition -UnifiedRoleDefinitionId $eligibility.RoleDefinitionId
        Write-Output "Group Name: $($group.Name), 分配类型: 合格, 角色名称: $($roleDefinition.DisplayName)"
    }
}

补充说明

  • 如果需要获取已激活的合格分配实例(即用户/组已从合格资格中激活的临时角色),可以使用Get-MgRoleManagementDirectoryRoleAssignmentScheduleInstance命令,过滤条件同样基于principalId。
  • 若遇到过滤条件不生效的情况,可尝试添加-All $true参数确保返回所有结果,避免分页导致数据遗漏。

内容的提问来源于stack exchange,提问作者cheerrycherry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 07:53:24