You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell批量添加用户到Azure DevOps组报错:Page Not Found

问题:获取Azure DevOps组描述符时出现404错误

批量将用户添加到新建的Azure DevOps组时,执行获取组描述符的请求:

$groupsUrl = "$apiUrl/graph/groups?api-version=6.0-preview.1"
$groups = Invoke-RestMethod -Uri $groupsUrl -Method Get -Headers $headers

触发错误:Invoke-RestMethod: Page Not Found。以下是完整脚本:

# Your Azure DevOps organization and PAT
$organization = " "
$personalAccessToken = " "
$apiUrl = "https://vsaex.dev.azure.com/$organization/_apis"

# Group name to add users to
$groupName = "  "

# Path to the CSV file
$csvFilePath = Resolve-Path "/Users/ /test.csv"

# Base64-encode the Personal Access Token and add it to the headers
$base64AuthInfo = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes(":$($personalAccessToken)"))
$headers = @{
    Authorization = "Basic $base64AuthInfo"
}

# Function to add a user to a group
function Add-UserToAzureDevOpsGroup {
    param(
        [string]$organization,
        [string]$groupId,
        [string]$memberId,
        [string]$pat
    )

    $uri = "https://vsaex.dev.azure.com/$organization/_apis/GroupEntitlements/$groupId/members/$memberId?api-version=7.0"

    $base64AuthInfo = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes(":$pat"))

    Invoke-RestMethod -Uri $uri -Method Put -Headers @{Authorization=("Basic $base64AuthInfo")} -ContentType "application/json"
}

# Get the descriptor of the group
$groupsUrl = "$apiUrl/graph/groups?api-version=6.0-preview.1"
$groups = Invoke-RestMethod -Uri $groupsUrl -Method Get -Headers $headers
$group = $groups.value | Where-Object { $_.principalName -eq $groupName }
$groupDescriptor = $group.descriptor

# Import the user list from the CSV
$users = Import-Csv -Path $csvFilePath

# Loop through each user and add them to the group
foreach ($user in $users) {
    $userEmail = $user.UserName
    $userDescriptorUrl = "$apiUrl/graph/users?api-version=6.0-preview.1&subjectTypes=user&mailAddress=$userEmail"
    $userDescriptorObject = Invoke-RestMethod -Uri $userDescriptorUrl -Method Get -Headers $headers
    $userDescriptor = $userDescriptorObject.value.descriptor

    if ($userDescriptor) {
        Add-UserToGroup -userDescriptor $userDescriptor -groupDescriptor $groupDescriptor
        Write-Host "Added user ($userEmail) to group ($groupName)"
    } else {
        Write-Host "Could not find user descriptor for email ($userEmail)"
    }
}

修复方案

1. 修正API基础域名

vsaex.dev.azure.com仅用于组织权限管理(如Group Entitlements),而**Graph API(身份/组查询)**的正确域名是vssps.dev.azure.com。修改API基础URL:

$apiUrl = "https://vssps.dev.azure.com/$organization/_apis"

2. 修正函数调用不匹配问题

原脚本中定义的函数是Add-UserToAzureDevOpsGroup,但调用时用了Add-UserToGroup,且参数名不匹配,修正调用语句:

Add-UserToAzureDevOpsGroup -organization $organization -groupId $groupDescriptor -memberId $userDescriptor -pat $personalAccessToken

3. (可选)使用稳定版API

将Graph API版本从预览版6.0-preview.1更新为稳定版7.1,提升兼容性:

# 获取组描述符的URL
$groupsUrl = "$apiUrl/graph/groups?api-version=7.1"
# 获取用户描述符的URL
$userDescriptorUrl = "$apiUrl/graph/users?api-version=7.1&subjectTypes=user&mailAddress=$userEmail"

修复后的完整脚本
# Your Azure DevOps organization and PAT
$organization = " "
$personalAccessToken = " "
$apiUrl = "https://vssps.dev.azure.com/$organization/_apis"

# Group name to add users to
$groupName = "  "

# Path to the CSV file
$csvFilePath = Resolve-Path "/Users/ /test.csv"

# Base64-encode the Personal Access Token and add it to the headers
$base64AuthInfo = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes(":$($personalAccessToken)"))
$headers = @{
    Authorization = "Basic $base64AuthInfo"
}

# Function to add a user to a group
function Add-UserToAzureDevOpsGroup {
    param(
        [string]$organization,
        [string]$groupId,
        [string]$memberId,
        [string]$pat
    )

    $uri = "https://vsaex.dev.azure.com/$organization/_apis/GroupEntitlements/$groupId/members/$memberId?api-version=7.0"

    $base64AuthInfo = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes(":$pat"))

    Invoke-RestMethod -Uri $uri -Method Put -Headers @{Authorization=("Basic $base64AuthInfo")} -ContentType "application/json"
}

# Get the descriptor of the group
$groupsUrl = "$apiUrl/graph/groups?api-version=7.1"
$groups = Invoke-RestMethod -Uri $groupsUrl -Method Get -Headers $headers
$group = $groups.value | Where-Object { $_.principalName -eq $groupName }
$groupDescriptor = $group.descriptor

# Import the user list from the CSV
$users = Import-Csv -Path $csvFilePath

# Loop through each user and add them to the group
foreach ($user in $users) {
    $userEmail = $user.UserName
    $userDescriptorUrl = "$apiUrl/graph/users?api-version=7.1&subjectTypes=user&mailAddress=$userEmail"
    $userDescriptorObject = Invoke-RestMethod -Uri $userDescriptorUrl -Method Get -Headers $headers
    $userDescriptor = $userDescriptorObject.value.descriptor

    if ($userDescriptor) {
        Add-UserToAzureDevOpsGroup -organization $organization -groupId $groupDescriptor -memberId $userDescriptor -pat $personalAccessToken
        Write-Host "Added user ($userEmail) to group ($groupName)"
    } else {
        Write-Host "Could not find user descriptor for email ($userEmail)"
    }
}

内容的提问来源于stack exchange,提问作者My ADO Obsession

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 09:25:57