如何通过控制台激活Azure特权身份管理(PIM)中的我的角色?
解决PIM角色激活的权限报错问题
背景
已通过以下PowerShell代码成功读取Microsoft Entra ID PIM中自己的角色:
$ScopeTypes=@('subscription','resourcegroup') Connect-AzAccount > $null Get-AzRoleEligibilitySchedule -Scope "/" -Filter "asTarget()" ` | Where-Object { $ScopeTypes -contains $_.ScopeType } ` | Group-Object RoleDefinitionDisplayName, Scope ` | Select-Object @{ Expression = { $_.group[0] } ; Label = 'Item' } ` | Select-Object -ExpandProperty item ` | Format-Table RoleDefinitionDisplayName, ScopeDisplayName, ScopeType
执行结果正常:
RoleDefinitionDisplayName ScopeDisplayName ScopeType ------------------------- ---------------- --------- Azure Kubernetes Service Cluster User Role ... resourcegroup Cognitive Services Contributor ... subscription Contributor ... resourcegroup Contributor ... resourcegroup Owner ... resourcegroup Reader ... subscription Reader ... subscription
问题
尝试用以下代码激活角色时,全部失败并报错权限不足:
$ScopeTypes = @('resourcegroup', 'subscription') Connect-AzAccount > $null Get-AzRoleEligibilitySchedule -Scope "/" -Filter "asTarget()" ` | Where-Object { $ScopeTypes -contains $_.ScopeType } ` | Group-Object RoleDefinitionDisplayName, Scope ` | Select-Object @{ Expression = { $_.group[0] } ; Label = 'Item' } ` | Select-Object -ExpandProperty item ` | ForEach-Object { $p = @{ Name = (New-Guid).Guid Scope = $_.Scope PrincipalId = $_.PrincipalId RoleDefinitionId = $_.RoleDefinitionId ScheduleInfoStartDateTime = Get-Date -Format o } New-AzRoleAssignmentScheduleRequest @p -ExpirationDuration PT8H -ExpirationType AfterDuration -RequestType SelfActivate -Justification "work" }
报错信息:
New-AzRoleAssignmentScheduleRequest_CreateExpanded: C:\dayforce\scripts\pim.ps1:28 Line | 28 | New-AzRoleAssignmentScheduleRequest @p -ExpirationDuration PT8H - … | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ | The requestor a...e does not have permissions for this request. Please use | $filter=asTarget() to filter on the requestor's assignments.
注:该用户可通过浏览器正常激活角色,但PowerShell操作失败。
解决方法
报错原因是手动构造的参数无法正确匹配到对应的PIM资格计划,导致权限校验不通过。正确的做法是使用Get-AzRoleEligibilitySchedule返回的资格计划ID(Id属性)来创建激活请求,而非单独指定Scope、PrincipalId等参数。
修正后的代码:
$ScopeTypes = @('resourcegroup', 'subscription') Connect-AzAccount > $null Get-AzRoleEligibilitySchedule -Scope "/" -Filter "asTarget()" ` | Where-Object { $ScopeTypes -contains $_.ScopeType } ` | Group-Object RoleDefinitionDisplayName, Scope ` | Select-Object @{ Expression = { $_.group[0] } ; Label = 'Item' } ` | Select-Object -ExpandProperty item ` | ForEach-Object { New-AzRoleAssignmentScheduleRequest ` -RoleEligibilityScheduleId $_.Id ` -ExpirationDuration PT8H ` -ExpirationType AfterDuration ` -RequestType SelfActivate ` -Justification "work" }
关键说明
- 使用
-RoleEligibilityScheduleId $_.Id直接关联已有的资格计划,确保请求能正确匹配到用户可激活的角色权限。 - 无需手动指定
Name、PrincipalId、Scope等参数,这些会自动从资格计划中关联获取,避免参数不匹配导致的权限错误。
内容的提问来源于stack exchange,提问作者mark
相关产品推荐
相关产品推荐

