You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过控制台激活Azure特权身份管理(PIM)中的我的角色?

解决PIM角色激活的权限报错问题

背景

已通过以下PowerShell代码成功读取Microsoft Entra ID PIM中自己的角色:

$ScopeTypes=@('subscription','resourcegroup')
Connect-AzAccount > $null
Get-AzRoleEligibilitySchedule -Scope "/" -Filter "asTarget()" `
| Where-Object { $ScopeTypes -contains $_.ScopeType } `
| Group-Object RoleDefinitionDisplayName, Scope `
| Select-Object @{ Expression = { $_.group[0] } ; Label = 'Item' } `
| Select-Object -ExpandProperty item `
| Format-Table RoleDefinitionDisplayName, ScopeDisplayName, ScopeType

执行结果正常:

RoleDefinitionDisplayName                  ScopeDisplayName   ScopeType
-------------------------                  ----------------   ---------
Azure Kubernetes Service Cluster User Role ...                resourcegroup
Cognitive Services Contributor             ...                subscription
Contributor                                ...                resourcegroup
Contributor                                ...                resourcegroup
Owner                                      ...                resourcegroup
Reader                                     ...                subscription
Reader                                     ...                subscription

问题

尝试用以下代码激活角色时,全部失败并报错权限不足:

$ScopeTypes = @('resourcegroup', 'subscription')

Connect-AzAccount > $null
Get-AzRoleEligibilitySchedule -Scope "/" -Filter "asTarget()" `
| Where-Object { $ScopeTypes -contains $_.ScopeType } `
| Group-Object RoleDefinitionDisplayName, Scope `
| Select-Object @{ Expression = { $_.group[0] } ; Label = 'Item' } `
| Select-Object -ExpandProperty item `
| ForEach-Object {
    $p = @{
        Name                      = (New-Guid).Guid
        Scope                     = $_.Scope
        PrincipalId               = $_.PrincipalId
        RoleDefinitionId          = $_.RoleDefinitionId
        ScheduleInfoStartDateTime = Get-Date -Format o
    }
    
    New-AzRoleAssignmentScheduleRequest @p -ExpirationDuration PT8H -ExpirationType AfterDuration -RequestType SelfActivate -Justification "work"
}

报错信息:

New-AzRoleAssignmentScheduleRequest_CreateExpanded: C:\dayforce\scripts\pim.ps1:28
Line |
 28 |      New-AzRoleAssignmentScheduleRequest @p -ExpirationDuration PT8H - …
     |      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     | The requestor a...e does not have permissions for this request. Please use
     | $filter=asTarget() to filter on the requestor's assignments.

注:该用户可通过浏览器正常激活角色,但PowerShell操作失败。

解决方法

报错原因是手动构造的参数无法正确匹配到对应的PIM资格计划,导致权限校验不通过。正确的做法是使用Get-AzRoleEligibilitySchedule返回的资格计划ID(Id属性)来创建激活请求,而非单独指定Scope、PrincipalId等参数。

修正后的代码:

$ScopeTypes = @('resourcegroup', 'subscription')

Connect-AzAccount > $null
Get-AzRoleEligibilitySchedule -Scope "/" -Filter "asTarget()" `
| Where-Object { $ScopeTypes -contains $_.ScopeType } `
| Group-Object RoleDefinitionDisplayName, Scope `
| Select-Object @{ Expression = { $_.group[0] } ; Label = 'Item' } `
| Select-Object -ExpandProperty item `
| ForEach-Object {
    New-AzRoleAssignmentScheduleRequest `
        -RoleEligibilityScheduleId $_.Id `
        -ExpirationDuration PT8H `
        -ExpirationType AfterDuration `
        -RequestType SelfActivate `
        -Justification "work"
}

关键说明

  • 使用-RoleEligibilityScheduleId $_.Id直接关联已有的资格计划,确保请求能正确匹配到用户可激活的角色权限。
  • 无需手动指定Name、PrincipalId、Scope等参数,这些会自动从资格计划中关联获取,避免参数不匹配导致的权限错误。

内容的提问来源于stack exchange,提问作者mark

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 17:06:12