You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用PowerShell检测GCCH环境下Outlook端点可达性的问题

解决GCCH环境下Outlook端点无人值守可达性检测问题

问题背景

需要每隔几分钟检测GCCH环境下多个微软服务端点的可达性,监控防火墙变更是否影响连接。但测试https://outlook.office365.us时,即使只用HEAD请求获取状态码也会返回401未授权,而无人值守脚本不想传递凭据。

原测试代码:

$ExchangeURL = Invoke-WebRequest -Uri https://outlook.office365.us -DisableKeepAlive -Method head | select StatusCode 
$TeamsURL = Invoke-WebRequest -Uri https://gov.teams.microsoft.us -DisableKeepAlive -Method head | select StatusCode
$OneDriveURL = Invoke-WebRequest -Uri https://redacted-my.sharepoint.us -DisableKeepAlive -Method head | select StatusCode
$SharepointURL = Invoke-WebRequest -Uri https://redacted-admin.sharepoint.us -DisableKeepAlive -Method head | select StatusCode
$AdminURL = Invoke-WebRequest -Uri https://portal.office365.us -DisableKeepAlive -Method head | select StatusCode

$ExchangeURL
$TeamsURL
$OneDriveURL
$SharepointURL
$AdminURL

执行报错:

Invoke-WebRequest : The remote server returned an error: (401) Unauthorized.
At C:\Users\jimbob\Desktop\Test_URL.ps1:3 char:16
+ ... changeURL = Invoke-WebRequest -Uri https://outlook.office365.us -Disa ...
+                 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : InvalidOperation: (System.Net.HttpWebRequest:HttpWebRequest) [Invoke-WebRequest], WebException
    + FullyQualifiedErrorId : WebCmdletWebResponseException,Microsoft.PowerShell.Commands.InvokeWebRequestCommand


StatusCode
----------
       200
       200
       200
       200

核心原因

GCCH环境下的Outlook端点对未授权的HEAD请求会强制身份验证,直接返回401,但我们的核心需求是验证防火墙是否允许连接到该端点,而非获取业务层面的200状态,因此可以换用更适合的检测方式。

解决方案

方案1:TCP端口连通性检测(推荐)

直接检测目标端点的443端口是否能连通,完全绕开HTTP授权问题,轻量且精准匹配防火墙监控需求。

# 定义需要检测的端点列表
$endpoints = @(
    @{ Name = "Outlook"; Uri = "outlook.office365.us"; Port = 443 },
    @{ Name = "Teams"; Uri = "gov.teams.microsoft.us"; Port = 443 },
    @{ Name = "OneDrive"; Uri = "redacted-my.sharepoint.us"; Port = 443 },
    @{ Name = "SharePoint Admin"; Uri = "redacted-admin.sharepoint.us"; Port = 443 },
    @{ Name = "Office Admin Portal"; Uri = "portal.office365.us"; Port = 443 }
)

# 批量检测并输出结果
foreach ($endpoint in $endpoints) {
    $isReachable = Test-NetConnection -ComputerName $endpoint.Uri -Port $endpoint.Port -InformationLevel Quiet
    [PSCustomObject]@{
        端点名称 = $endpoint.Name
        地址     = $endpoint.Uri
        可达状态 = if ($isReachable) { "正常" } else { "阻断" }
        检测时间 = Get-Date -Format "yyyy-MM-dd HH:mm:ss"
    }
}

方案2:HTTP请求忽略错误检测

如果需要保留HTTP层面的状态码信息,可以通过-SkipHttpErrorCheck参数跳过401错误,并区分“连接失败(防火墙阻断)”和“HTTP错误(已连通但未授权)”。

# 定义需要检测的URL列表
$urls = @(
    @{ Name = "Outlook"; Url = "https://outlook.office365.us" },
    @{ Name = "Teams"; Url = "https://gov.teams.microsoft.us" },
    @{ Name = "OneDrive"; Url = "https://redacted-my.sharepoint.us" },
    @{ Name = "SharePoint Admin"; Url = "https://redacted-admin.sharepoint.us" },
    @{ Name = "Office Admin Portal"; Url = "https://portal.office365.us" }
)

# 批量检测并输出结果
foreach ($item in $urls) {
    try {
        $response = Invoke-WebRequest -Uri $item.Url -DisableKeepAlive -Method Head -SkipHttpErrorCheck -ErrorAction Stop
        $statusCode = $response.StatusCode
        $reachable = $true
    }
    catch {
        # 判断是连接失败还是HTTP错误
        if ($_.Exception.Message -match "无法连接" -or $_.Exception.Message -match "无法建立连接") {
            $statusCode = "连接失败"
            $reachable = $false
        }
        else {
            $statusCode = $_.Exception.Response.StatusCode.Value__
            $reachable = $true
        }
    }
    [PSCustomObject]@{
        端点名称 = $item.Name
        URL地址  = $item.Url
        状态码   = $statusCode
        可达状态 = if ($reachable) { "正常(防火墙未阻断)" } else { "阻断" }
        检测时间 = Get-Date -Format "yyyy-MM-dd HH:mm:ss"
    }
}

说明

  • 方案1更适合防火墙变更监控,因为只要端口能连通,就说明防火墙没有拦截该端点;
  • 方案2可以同时获取HTTP状态码,即使返回401,也代表请求已经到达目标服务器,防火墙未阻断,满足监控需求。

内容的提问来源于stack exchange,提问作者Tekwhat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 16:27:34