You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Microsoft Graph PowerShell读取Azure PIM中的我的角色

问题描述
  • 我可通过Azure门户访问PIM角色管理界面,需要批量激活5个角色,但GUI操作体验极差,希望通过脚本实现自动化,首要目标是程序化读取该界面的角色信息。
  • 明确要求使用最新的Microsoft Graph PowerShell模块,拒绝AzureADPreview、msal.ps等过时模块方案。
当前遇到的权限问题

执行Connect-MgGraph完成连接后,尝试调用以下命令读取角色资源:

Get-MgBetaPrivilegedAccessResource -PrivilegedAccessId AzureResources

触发403权限错误,具体信息如下:

Get-MgBetaPrivilegedAccessResource_List: {"errorCode":"PermissionScopeNotGranted","message":"Authorization failed due to missing permission scope PrivilegedAccess.Read.AzureResources,PrivilegedAccess.ReadWrite.AzureResources.","instanceAnnotations":[]}

Status: 403 (Forbidden)
ErrorCode: UnknownError
Date: 2023-12-04T18:24:46

Headers:
Cache-Control : private
Transfer-Encoding : chunked
Vary : Accept-Encoding
Strict-Transport-Security : max-age=31536000
request-id : 91036c22-82da-4c5b-8d18-ed77dd9902f8
client-request-id : 775dd1f0-cbf0-45cd-899b-4a953a70a8fc
x-ms-ags-diagnostic : {"ServerInfo":{"DataCenter":"Canada Central","Slice":"E","Ring":"5","ScaleUnit":"002","RoleInstance":"YT2PEPF00000162"}}
Date : Mon, 04 Dec 2023 18:24:45 GMT

  • 尝试添加权限重新连接:Connect-MgGraph -Scopes PrivilegedAccess.ReadWrite.AzureResources,但该操作需要管理员权限,我无此权限,此路径不可行。
  • 尝试添加过滤条件缩小查询范围:
Get-MgBetaPrivilegedAccessResource -PrivilegedAccessId AzureResources -Filter "Type eq 'subscription' And DisplayName eq 'SUBSCRIPTION-I-CAN-ACCESS'"

仍触发相同的403权限错误。

后续进展(编辑3)

通过Az模块方案实现了角色读取需求:

$ScopeTypes = @('resourcegroup', 'subscription')

Connect-AzAccount
Get-AzRoleEligibilitySchedule -Scope "/" -Filter "asTarget()" `
| Where-Object { $ScopeTypes -contains $_.ScopeType } `
| Group-Object RoleDefinitionDisplayName, Scope `
| Select-Object @{ Expression = { $_.group[0] } ; Label = 'Item' } `
| Select-Object -ExpandProperty item `
| ForEach-Object {
    $p = @{
        Name                      = (New-Guid).Guid
        Scope                     = $_.Scope
        PrincipalId               = $_.PrincipalId
        RoleDefinitionId          = $_.RoleDefinitionId
        ScheduleInfoStartDateTime = Get-Date -Format o
    }
    
    New-AzRoleAssignmentScheduleRequest @p -ExpirationDuration PT8H -ExpirationType AfterDuration -RequestType SelfActivate -Justification "work"
}
  • Get-AzRoleEligibilitySchedule成功返回了我拥有的可激活角色,读取角色信息的需求已解决。
  • 但New-AzRoleAssignmentScheduleRequest执行失败,错误信息如下:

New-AzRoleAssignmentScheduleRequest_CreateExpanded: C:\dayforce\scripts\pim.ps1:28
Line |
28 | New-AzRoleAssignmentScheduleRequest @p -ExpirationDuration PT8H - …
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
| The requestor a...e does not have permissions for this request. Please use
| $filter=asTarget() to filter on the requestor's assignments.

确认报错中的ID为我的用户对象ID,且我可在浏览器中手动激活角色,但脚本执行失败。关于角色激活的问题将另行提问。

内容的提问来源于stack exchange,提问作者mark

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 22:50:34