如何使用Microsoft Graph PowerShell读取Azure PIM中的我的角色
- 我可通过Azure门户访问PIM角色管理界面,需要批量激活5个角色,但GUI操作体验极差,希望通过脚本实现自动化,首要目标是程序化读取该界面的角色信息。
- 明确要求使用最新的Microsoft Graph PowerShell模块,拒绝AzureADPreview、msal.ps等过时模块方案。
执行Connect-MgGraph完成连接后,尝试调用以下命令读取角色资源:
Get-MgBetaPrivilegedAccessResource -PrivilegedAccessId AzureResources
触发403权限错误,具体信息如下:
Get-MgBetaPrivilegedAccessResource_List: {"errorCode":"PermissionScopeNotGranted","message":"Authorization failed due to missing permission scope PrivilegedAccess.Read.AzureResources,PrivilegedAccess.ReadWrite.AzureResources.","instanceAnnotations":[]}
Status: 403 (Forbidden)
ErrorCode: UnknownError
Date: 2023-12-04T18:24:46Headers:
Cache-Control : private
Transfer-Encoding : chunked
Vary : Accept-Encoding
Strict-Transport-Security : max-age=31536000
request-id : 91036c22-82da-4c5b-8d18-ed77dd9902f8
client-request-id : 775dd1f0-cbf0-45cd-899b-4a953a70a8fc
x-ms-ags-diagnostic : {"ServerInfo":{"DataCenter":"Canada Central","Slice":"E","Ring":"5","ScaleUnit":"002","RoleInstance":"YT2PEPF00000162"}}
Date : Mon, 04 Dec 2023 18:24:45 GMT
- 尝试添加权限重新连接:
Connect-MgGraph -Scopes PrivilegedAccess.ReadWrite.AzureResources,但该操作需要管理员权限,我无此权限,此路径不可行。 - 尝试添加过滤条件缩小查询范围:
Get-MgBetaPrivilegedAccessResource -PrivilegedAccessId AzureResources -Filter "Type eq 'subscription' And DisplayName eq 'SUBSCRIPTION-I-CAN-ACCESS'"
仍触发相同的403权限错误。
通过Az模块方案实现了角色读取需求:
$ScopeTypes = @('resourcegroup', 'subscription') Connect-AzAccount Get-AzRoleEligibilitySchedule -Scope "/" -Filter "asTarget()" ` | Where-Object { $ScopeTypes -contains $_.ScopeType } ` | Group-Object RoleDefinitionDisplayName, Scope ` | Select-Object @{ Expression = { $_.group[0] } ; Label = 'Item' } ` | Select-Object -ExpandProperty item ` | ForEach-Object { $p = @{ Name = (New-Guid).Guid Scope = $_.Scope PrincipalId = $_.PrincipalId RoleDefinitionId = $_.RoleDefinitionId ScheduleInfoStartDateTime = Get-Date -Format o } New-AzRoleAssignmentScheduleRequest @p -ExpirationDuration PT8H -ExpirationType AfterDuration -RequestType SelfActivate -Justification "work" }
Get-AzRoleEligibilitySchedule成功返回了我拥有的可激活角色,读取角色信息的需求已解决。- 但
New-AzRoleAssignmentScheduleRequest执行失败,错误信息如下:
New-AzRoleAssignmentScheduleRequest_CreateExpanded: C:\dayforce\scripts\pim.ps1:28
Line |
28 | New-AzRoleAssignmentScheduleRequest @p -ExpirationDuration PT8H - …
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
| The requestor a...e does not have permissions for this request. Please use
| $filter=asTarget() to filter on the requestor's assignments.
确认报错中的ID为我的用户对象ID,且我可在浏览器中手动激活角色,但脚本执行失败。关于角色激活的问题将另行提问。
内容的提问来源于stack exchange,提问作者mark

