You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

寻找激活特权安全组PIM的MS Graph PowerShell类似命令

特权安全组PIM激活的PowerShell命令方案

针对特权安全组的Privileged Identity Management(PIM)激活,确实有对应的Microsoft Graph PowerShell命令,替代角色类命令的方案如下:

关键命令说明

  • 获取用户的特权组资格实例:替代角色类的Get-MgRoleManagementDirectoryRoleEligibilityScheduleInstance,使用组专属的Get-MgIdentityGovernancePrivilegedAccessGroupEligibilityScheduleInstance,用于查询用户具备激活资格的特权安全组记录。
  • 发起组激活请求:使用New-MgIdentityGovernancePrivilegedAccessGroupAssignmentScheduleRequest创建激活请求,完成特权组身份的激活操作。

示例脚本片段

# 替换为实际的用户ID和特权组ID
$userId = "xxxxxx-xxxx-xxxx-xxxx-xxxxxx"
$privilegedGroupId = "yyyyyy-yyyy-yyyy-yyyy-yyyyyy"

# 获取用户的该特权组资格实例
$groupEligibility = Get-MgIdentityGovernancePrivilegedAccessGroupEligibilityScheduleInstance `
    -Filter "principalId eq '$userId' and groupId eq '$privilegedGroupId'"

# 发起激活请求,设置8小时有效期,可根据需求调整
New-MgIdentityGovernancePrivilegedAccessGroupAssignmentScheduleRequest `
    -RequestBody @{
        Action = "activate"
        Justification = "业务操作需要临时激活特权组权限"
        ScheduleInfo = @{
            StartDateTime = Get-Date
            Expiration = @{
                Type = "afterDuration"
                Duration = "PT8H" # ISO 8601格式,PT8H代表8小时
            }
        }
        TargetScheduleInstanceId = $groupEligibility.Id
        PrincipalId = $userId
        GroupId = $privilegedGroupId
    }

注意事项

  1. 确保已安装并更新至最新版Microsoft Graph PowerShell模块:
    Update-Module Microsoft.Graph
    
  2. 需要提前授予对应的Graph API权限,例如PrivilegedAccess.ReadWrite.AzureADGroup,可通过Connect-MgGraph -Scopes "PrivilegedAccess.ReadWrite.AzureADGroup"进行权限授权。

内容的提问来源于stack exchange,提问作者Yashas .M

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 05:33:19