You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Azure CLI替代PowerShell在Entra ID中创建自定义角色

使用Azure CLI在Entra ID中创建自定义角色

前提条件

  • 拥有Global Administrator或Privileged Role Administrator权限
  • 已在Azure Cloud Shell中完成Azure CLI登录(未登录可执行az login)

步骤1:编写自定义角色JSON定义文件

在Cloud Shell中创建包含角色权限的JSON配置文件,示例模拟原文档中用户账户管理类的自定义角色权限:

cat > custom-user-admin-role.json << EOF
{
  "description": "自定义角色:管理用户账户的创建、删除及基础信息更新",
  "displayName": "Custom User Account Manager",
  "isEnabled": true,
  "rolePermissions": [
    {
      "allowedResourceActions": [
        "microsoft.directory/users/create",
        "microsoft.directory/users/delete",
        "microsoft.directory/users/basic/update",
        "microsoft.directory/users/password/update"
      ],
      "condition": null
    }
  ],
  "scopes": [
    "/"
  ]
}
EOF

说明:rolePermissions内的权限动作可按需调整;scopes设为"/"表示作用于整个租户,也可指定特定OU或对象范围。

步骤2:创建自定义角色

执行CLI命令导入JSON文件创建角色:

az ad role definition create --role-definition @custom-user-admin-role.json

步骤3:验证角色创建结果

查看所有自定义角色:

az ad role definition list --custom-filter "IsCustomRole eq true" --output table

查看指定角色的详细配置:

az ad role definition show --id <角色ID>

步骤4:分配自定义角色

给单个用户分配角色:

az ad role assignment create --assignee <用户ID或UPN> --role "Custom User Account Manager" --scope "/"

给安全组分配角色:

az ad role assignment create --assignee <组ID> --role "Custom User Account Manager" --scope "/"

步骤5:删除自定义角色(可选)

若需清理角色,执行:

az ad role definition delete --id <角色ID>

内容的提问来源于stack exchange,提问作者user3698547

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 07:03:12