如何从Microsoft Purview门户编程导出敏感信息类型匹配数据?
能否通过PowerShell/C#提取Microsoft Purview内容资源管理器中的敏感信息?
可行性说明
具备相应权限(如Compliance Administrator、Content Explorer Viewer、Compliance Search等角色)的前提下,完全可以通过编程方式提取敏感信息类型及对应文档数据。
PowerShell实现方法
步骤1:安装并连接合规中心PowerShell模块
# 安装Exchange Online Management模块(包含合规中心cmdlet) Install-Module -Name ExchangeOnlineManagement -Force # 连接到合规中心 Connect-IPPSSession
步骤2:获取所有敏感信息类型
# 列出所有已配置的敏感信息类型 Get-DlpSensitiveInformationType
步骤3:搜索并提取包含特定敏感信息的文档
# 1. 创建合规搜索任务,指定目标敏感信息类型 New-ComplianceSearch -Name "CreditCard_Search" -ExchangeLocation All -ContentMatchQuery "sensitiveinformationtype:'Credit Card Number'" # 2. 启动搜索任务 Start-ComplianceSearch -Identity "CreditCard_Search" # 3. 等待搜索完成后,获取并解析结果 # 可通过Get-ComplianceSearch查看状态,当Status为Completed时执行以下命令 Get-ComplianceSearchResult -Identity "CreditCard_Search" -Format Json | ConvertFrom-Json
C#实现方法(基于Microsoft Graph API)
步骤1:准备Azure AD应用与权限
- 在Azure AD中注册应用,添加Application权限:
SecurityEvents.Read.All、ComplianceContent.Read.All、ComplianceSearch.ReadWrite.All - 授予管理员同意,获取客户端ID、租户ID、客户端密钥(或证书)用于获取访问令牌
步骤2:示例代码
using System; using System.Net.Http; using System.Net.Http.Headers; using System.Text.Json; using System.Threading.Tasks; namespace PurviewDataExtraction { class Program { static async Task Main(string[] args) { string tenantId = "YOUR_TENANT_ID"; string clientId = "YOUR_CLIENT_ID"; string clientSecret = "YOUR_CLIENT_SECRET"; string accessToken = await GetAccessToken(tenantId, clientId, clientSecret); using var httpClient = new HttpClient(); httpClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", accessToken); // 1. 获取所有敏感信息类型 var sitResponse = await httpClient.GetAsync("https://graph.microsoft.com/v1.0/security/sensitiveInformationTypes"); if (sitResponse.IsSuccessStatusCode) { var sitContent = await sitResponse.Content.ReadAsStringAsync(); Console.WriteLine("敏感信息类型列表:\n" + sitContent); } // 2. 创建并执行合规搜索 var searchRequest = new { displayName = "CreditCard_Doc_Search", contentQuery = "sensitiveinformationtype:'Credit Card Number'", exchangeLocations = new[] { new { location = "All" } } }; var createSearchResponse = await httpClient.PostAsJsonAsync( "https://graph.microsoft.com/v1.0/security/complianceSearches", searchRequest); if (createSearchResponse.IsSuccessStatusCode) { var searchResult = await createSearchResponse.Content.ReadFromJsonAsync<JsonElement>(); string searchId = searchResult.GetProperty("id").GetString(); // 启动搜索 await httpClient.PostAsync($"https://graph.microsoft.com/v1.0/security/complianceSearches/{searchId}/start", null); // 轮询等待搜索完成(实际场景需优化轮询逻辑) await Task.Delay(30000); // 示例等待30秒 // 获取搜索结果 var searchResultsResponse = await httpClient.GetAsync($"https://graph.microsoft.com/v1.0/security/complianceSearches/{searchId}/results"); if (searchResultsResponse.IsSuccessStatusCode) { var resultsContent = await searchResultsResponse.Content.ReadAsStringAsync(); Console.WriteLine("\n包含敏感信息的文档结果:\n" + resultsContent); } } } static async Task<string> GetAccessToken(string tenantId, string clientId, string clientSecret) { using var httpClient = new HttpClient(); var requestBody = new FormUrlEncodedContent(new[] { new KeyValuePair<string, string>("grant_type", "client_credentials"), new KeyValuePair<string, string>("client_id", clientId), new KeyValuePair<string, string>("client_secret", clientSecret), new KeyValuePair<string, string>("scope", "https://graph.microsoft.com/.default") }); var response = await httpClient.PostAsync($"https://login.microsoftonline.com/{tenantId}/oauth2/v2.0/token", requestBody); response.EnsureSuccessStatusCode(); var tokenContent = await response.Content.ReadFromJsonAsync<JsonElement>(); return tokenContent.GetProperty("access_token").GetString(); } } }
注意事项
- 权限验证:确保执行操作的账号或应用拥有对应权限,避免访问被拒绝
- 速率限制:合规搜索及Graph API存在速率限制,需合理控制请求频率
- 结果解析:返回的JSON结果包含文档路径、敏感信息匹配详情等,可根据业务需求进一步处理
内容的提问来源于stack exchange,提问作者in-pv
相关产品推荐
相关产品推荐

