如何获取Intune中所有detectedApp关联的全部托管设备ID?
批量获取DetectedApp关联托管设备ID的可行方案
核心问题复盘
你尝试通过$expand关联查询detectedApp与托管设备时返回空数组,逐个查询触发429限流,反向查询设备的detectedApps也无结果,需要批量获取所有detectedApp对应的托管设备ID。
可行解决方法
方法1:批量请求+分页规避限流
拉取全量detectedApp基础信息
用分页方式批量获取所有detectedApp的ID和名称,单次最多拉取999条:GET https://graph.microsoft.com/beta/deviceManagement/detectedApps?$select=id,displayName&$top=999通过响应头的
@odata.nextLink循环拉取所有分页数据,收集全部detectedApp的ID。构造批量请求查询关联设备
将收集到的detectedApp ID按每20个一组拆分(Microsoft Graph批量请求最多支持20个子请求),构造如下请求体后发送POST请求到https://graph.microsoft.com/beta/$batch:{ "requests": [ { "id": "1", "method": "GET", "url": "/deviceManagement/detectedApps/{detectedAppId1}/managedDevices?$select=id" }, { "id": "2", "method": "GET", "url": "/deviceManagement/detectedApps/{detectedAppId2}/managedDevices?$select=id" } // 最多添加20个此类子请求 ] }若遇到429限流,需根据响应头的
Retry-After值进行重试,避免频繁请求。
方法2:使用导出API批量导出(推荐)
通过设备管理导出API直接生成包含关联关系的全量数据集,无需逐个查询:
- 创建导出任务
发送POST请求:POST https://graph.microsoft.com/beta/deviceManagement/reports/exportJobs Content-Type: application/json { "reportName": "detectedApps_devices_association", "filter": "", "select": "detectedAppId,detectedAppDisplayName,managedDeviceId", "format": "csv", "localizationType": "none" } - 轮询任务状态并下载结果
接收响应中的exportJob.id,定时发送GET请求查询状态:
当GET https://graph.microsoft.com/beta/deviceManagement/reports/exportJobs/{exportJobId}status变为completed时,使用响应中的url字段下载CSV文件,文件中包含所有detectedApp与托管设备的关联ID。
空数组问题排查
之前查询返回空数组大概率是权限问题:
- 确保账号/应用拥有
DeviceManagementManagedDevices.Read.All和DeviceManagementApps.Read.All权限(应用权限优先,适合批量操作场景); - 优先使用beta版本API,v1.0版本的关联查询存在兼容性缺陷。
内容的提问来源于stack exchange,提问作者zaitsman
相关产品推荐
相关产品推荐

