You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD安全组问题:可从CSV添加用户,无法移除不在CSV中的成员

解决Azure AD安全组同步问题:移除CSV外的用户

我能通过CSV文件将用户添加到Azure AD安全组,但无法移除组中不在CSV内的现有用户。目前添加功能正常,原脚本如下:

#Connect to Azure AD 
Connect-AzureAD

#Import the list and save it to a variable
$list = Import-Csv "H:\BPT_Users_Reports\SCJ_BPT_Users_03-07-2024_test.csv"
#Insert the display name of the group here
$group = "BPT User Load Test"

#Retrieve the group name for use later in the script
$GroupObjectID = Get-AzureADGroup -SearchString $group | Select -Property ObjectID

#roll through the list to look up each user and add to the group. 
foreach ($y in $list){
    $y2 = Get-AzureADUser -ObjectId $y.userPrincipalName | Select -Property ObjectID
    $members = Get-AzureADGroupMember -ObjectId $GroupObjectID.ObjectID -All $true

    if ($y2.ObjectID -in $members.ObjectID) {
        Write-Host $y.userPrincipalName 'is already in the Group' -ForegroundColor Blue
    }else{
        Add-AzureADGroupMember -ObjectId $GroupObjectID.ObjectID -RefObjectId $y2.ObjectId -InformationAction SilentlyContinue
        Write-Host $y.userPrincipalName 'has been added to the Group' -ForegroundColor Green
    }
}

#Disconnect Azure AD
Disconnect-AzureAD

我尝试添加额外的ForEach语句实现移除功能,但脚本执行后没有实际移除用户,尝试的代码如下:

ForEach ($y in $list)
{
    {        
        $UserObj = Get-AzureADUser -ObjectId $y.UPN
        Where-Object {$Group -notcontains $y.UPN}
        Remove-AzureADGroupMember -ObjectID $Group.ObjectID -RfObjectId.ObjectID 
    }
}   

修正后的完整脚本

要实现组内仅保留CSV中用户的同步效果,需调整逻辑:先获取组内所有成员,对比CSV用户列表,移除不在列表中的成员。同时优化API调用次数提升效率:

# 连接Azure AD
Connect-AzureAD

# 导入CSV用户列表
$csvUsers = Import-Csv "H:\BPT_Users_Reports\SCJ_BPT_Users_03-07-2024_test.csv"
# 目标组名称
$targetGroupName = "BPT User Load Test"

# 获取目标组的ObjectID
$targetGroup = Get-AzureADGroup -SearchString $targetGroupName
if (-not $targetGroup) {
    Write-Host "未找到目标组 $targetGroupName" -ForegroundColor Red
    Disconnect-AzureAD
    exit
}
$groupObjectId = $targetGroup.ObjectID

# 提前获取组内所有成员(仅一次调用,提升效率)
$currentMembers = Get-AzureADGroupMember -ObjectId $groupObjectId -All $true | Where-Object {$_.ObjectType -eq "User"}
# 提取CSV中的用户UPN列表
$csvUserUpns = $csvUsers.userPrincipalName | Sort-Object -Unique

# ----------------------
# 步骤1:添加CSV中存在但组内没有的用户
# ----------------------
foreach ($user in $csvUsers) {
    $userUpn = $user.userPrincipalName
    $userObject = Get-AzureADUser -ObjectId $userUpn -ErrorAction SilentlyContinue
    if (-not $userObject) {
        Write-Host "CSV中的用户 $userUpn 不存在于Azure AD" -ForegroundColor Yellow
        continue
    }

    if ($userObject.ObjectID -in $currentMembers.ObjectID) {
        Write-Host "$userUpn 已在组内" -ForegroundColor Blue
    } else {
        Add-AzureADGroupMember -ObjectId $groupObjectId -RefObjectId $userObject.ObjectID -InformationAction SilentlyContinue
        Write-Host "$userUpn 已添加到组" -ForegroundColor Green
    }
}

# ----------------------
# 步骤2:移除组内存在但CSV中没有的用户
# ----------------------
foreach ($member in $currentMembers) {
    $memberUpn = $member.UserPrincipalName
    if ($memberUpn -notin $csvUserUpns) {
        Remove-AzureADGroupMember -ObjectId $groupObjectId -RefObjectId $member.ObjectID -InformationAction SilentlyContinue
        Write-Host "$memberUpn 已从组内移除" -ForegroundColor Red
    }
}

# 断开Azure AD连接
Disconnect-AzureAD

关键优化点

  1. 减少API调用:仅一次获取组内所有成员,避免原脚本中每次循环都调用Get-AzureADGroupMember
  2. 逻辑修正:遍历组内成员而非CSV用户,筛选出不在CSV中的用户执行移除
  3. 错误处理:增加用户不存在的判断,避免无效操作
  4. 参数修正:修正了Remove-AzureADGroupMember的参数拼写错误(原尝试中的-RfObjectId.ObjectID应为-RefObjectId)

内容的提问来源于stack exchange,提问作者Eddie Crandall

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 12:50:22