Azure PowerShell批量获取所有用户角色分配(含-ExpandPrincipalGroups)报错求助
Fix: "Cannot find principal" Error When Bulk Fetching Azure User Role Assignments with
-ExpandPrincipalGroups Looks like you ran into a common pitfall when working with Azure PowerShell role assignments in bulk! Let's break down why this is happening and fix it step by step.
What's Causing the Error?
Your current script has two main issues:
- Incorrect variable handling: You're assigning an array of all user UPNs to
$user, then passing that entire array directly to-SignInName—this parameter only accepts a single user principal name, not an array. - Invalid/empty user entries: Some users in your tenant might be disabled, soft-deleted, or have no role assignments (including inherited group permissions), which triggers the "Cannot find principal" error when the command tries to query them.
Corrected Script with Error Handling
Here's a robust script that fixes both problems, with proper looping and error catching:
# Get only active, non-deleted Azure AD users to avoid invalid principals $activeUsers = Get-AzADUser | Where-Object { $_.AccountEnabled -eq $true -and $_.DeletedDateTime -eq $null } # Initialize an array to collect results (optional, for exporting later) $roleAssignmentResults = @() # Loop through each user individually foreach ($user in $activeUsers) { try { # Fetch role assignments including those inherited from groups $assignments = Get-AzRoleAssignment -SignInName $user.UserPrincipalName -ExpandPrincipalGroups -ErrorAction Stop # Add results to our collection and output to console $roleAssignmentResults += $assignments | Select-Object DisplayName, RoleDefinitionName, Scope $assignments | Select-Object DisplayName, RoleDefinitionName, Scope } catch [Microsoft.Azure.Commands.Resources.Common.KeyNotFoundException] { # Skip users that can't be found and log a warning Write-Warning "Skipping user $($user.UserPrincipalName): Principal not found (likely disabled/deleted or no role assignments)" } catch { # Catch all other unexpected errors Write-Error "Unexpected error processing $($user.UserPrincipalName): $_" } } # Optional: Export results to a CSV file for analysis $roleAssignmentResults | Export-Csv -Path "AzureUserRoleAssignments.csv" -NoTypeInformation -Encoding UTF8
Key Improvements Explained
- Filter active users: We exclude disabled and soft-deleted users upfront to reduce unnecessary errors.
- Individual user processing: Using
foreachensures we pass only one UPN to-SignInNameat a time, which matches the parameter's requirements. - Targeted error handling: We specifically catch the "principal not found" error to skip problematic users without breaking the entire script.
- Result collection: The optional array lets you export all valid role assignments to a CSV for easier review.
Quick Troubleshooting Tip
If you still see errors for some active users, double-check if those users have any role assignments (direct or group-inherited)—if they don't, the command will still throw the "principal not found" error, which our script handles gracefully with a warning.
内容的提问来源于stack exchange,提问作者Suri007
相关产品推荐
相关产品推荐

