Azure AD安全组问题:可从CSV添加用户,无法移除不在CSV中的成员
解决Azure AD安全组同步问题:移除CSV外的用户
我能通过CSV文件将用户添加到Azure AD安全组,但无法移除组中不在CSV内的现有用户。目前添加功能正常,原脚本如下:
#Connect to Azure AD Connect-AzureAD #Import the list and save it to a variable $list = Import-Csv "H:\BPT_Users_Reports\SCJ_BPT_Users_03-07-2024_test.csv" #Insert the display name of the group here $group = "BPT User Load Test" #Retrieve the group name for use later in the script $GroupObjectID = Get-AzureADGroup -SearchString $group | Select -Property ObjectID #roll through the list to look up each user and add to the group. foreach ($y in $list){ $y2 = Get-AzureADUser -ObjectId $y.userPrincipalName | Select -Property ObjectID $members = Get-AzureADGroupMember -ObjectId $GroupObjectID.ObjectID -All $true if ($y2.ObjectID -in $members.ObjectID) { Write-Host $y.userPrincipalName 'is already in the Group' -ForegroundColor Blue }else{ Add-AzureADGroupMember -ObjectId $GroupObjectID.ObjectID -RefObjectId $y2.ObjectId -InformationAction SilentlyContinue Write-Host $y.userPrincipalName 'has been added to the Group' -ForegroundColor Green } } #Disconnect Azure AD Disconnect-AzureAD
我尝试添加额外的ForEach语句实现移除功能,但脚本执行后没有实际移除用户,尝试的代码如下:
ForEach ($y in $list) { { $UserObj = Get-AzureADUser -ObjectId $y.UPN Where-Object {$Group -notcontains $y.UPN} Remove-AzureADGroupMember -ObjectID $Group.ObjectID -RfObjectId.ObjectID } }
修正后的完整脚本
要实现组内仅保留CSV中用户的同步效果,需调整逻辑:先获取组内所有成员,对比CSV用户列表,移除不在列表中的成员。同时优化API调用次数提升效率:
# 连接Azure AD Connect-AzureAD # 导入CSV用户列表 $csvUsers = Import-Csv "H:\BPT_Users_Reports\SCJ_BPT_Users_03-07-2024_test.csv" # 目标组名称 $targetGroupName = "BPT User Load Test" # 获取目标组的ObjectID $targetGroup = Get-AzureADGroup -SearchString $targetGroupName if (-not $targetGroup) { Write-Host "未找到目标组 $targetGroupName" -ForegroundColor Red Disconnect-AzureAD exit } $groupObjectId = $targetGroup.ObjectID # 提前获取组内所有成员(仅一次调用,提升效率) $currentMembers = Get-AzureADGroupMember -ObjectId $groupObjectId -All $true | Where-Object {$_.ObjectType -eq "User"} # 提取CSV中的用户UPN列表 $csvUserUpns = $csvUsers.userPrincipalName | Sort-Object -Unique # ---------------------- # 步骤1:添加CSV中存在但组内没有的用户 # ---------------------- foreach ($user in $csvUsers) { $userUpn = $user.userPrincipalName $userObject = Get-AzureADUser -ObjectId $userUpn -ErrorAction SilentlyContinue if (-not $userObject) { Write-Host "CSV中的用户 $userUpn 不存在于Azure AD" -ForegroundColor Yellow continue } if ($userObject.ObjectID -in $currentMembers.ObjectID) { Write-Host "$userUpn 已在组内" -ForegroundColor Blue } else { Add-AzureADGroupMember -ObjectId $groupObjectId -RefObjectId $userObject.ObjectID -InformationAction SilentlyContinue Write-Host "$userUpn 已添加到组" -ForegroundColor Green } } # ---------------------- # 步骤2:移除组内存在但CSV中没有的用户 # ---------------------- foreach ($member in $currentMembers) { $memberUpn = $member.UserPrincipalName if ($memberUpn -notin $csvUserUpns) { Remove-AzureADGroupMember -ObjectId $groupObjectId -RefObjectId $member.ObjectID -InformationAction SilentlyContinue Write-Host "$memberUpn 已从组内移除" -ForegroundColor Red } } # 断开Azure AD连接 Disconnect-AzureAD
关键优化点
- 减少API调用:仅一次获取组内所有成员,避免原脚本中每次循环都调用
Get-AzureADGroupMember - 逻辑修正:遍历组内成员而非CSV用户,筛选出不在CSV中的用户执行移除
- 错误处理:增加用户不存在的判断,避免无效操作
- 参数修正:修正了
Remove-AzureADGroupMember的参数拼写错误(原尝试中的-RfObjectId.ObjectID应为-RefObjectId)
内容的提问来源于stack exchange,提问作者Eddie Crandall
相关产品推荐
相关产品推荐

