You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否通过内置KQL函数或变通方法在ADX管理查询中获取服务主体详情?

在ADX中查询其他AAD主体详情的方法

一、内置函数限制说明

目前Kusto没有直接查询任意AAD主体详情的内置函数,ADX的KQL函数主要聚焦于自身权限上下文及集群/数据库的管理操作,无法直接调用AAD或Microsoft Graph接口获取外部主体信息。

二、变通方法

1. 集成Microsoft Graph API查询

通过external_data运算符调用Microsoft Graph API,可获取AAD主体的详细信息。执行此操作的主体需具备调用Graph相关接口的权限(如User.Read.All、Application.Read.All等)。

示例查询(针对服务主体):

external_data(id:string, displayName:string, appId:string, servicePrincipalType:string)
[h@"https://graph.microsoft.com/v1.0/servicePrincipals?$filter=id eq '<目标AAD GUID>'"]
with (format = "json", ingestionMapping = 
    @"[{""Column"":""id"",""Properties"":{""Path"":""$.value[0].id""}},
      {""Column"":""displayName"",""Properties"":{""Path"":""$.value[0].displayName""}},
      {""Column"":""appId"",""Properties"":{""Path"":""$.value[0].appId""}},
      {""Column"":""servicePrincipalType"",""Properties"":{""Path"":""$.value[0].servicePrincipalType""}}]"
)

2. 批量处理控制命令中的主体ID

结合.show commands-and-queries提取服务主体ID,再批量调用Graph API:

// 提取命令记录中的服务主体ID
.show commands-and-queries
| where StartedBy startswith "app:"
| parse StartedBy with "app:" principalId:string
| distinct principalId
// 对每个ID调用Graph API(示例为单ID扩展逻辑)
| extend graphEndpoint = strcat("https://graph.microsoft.com/v1.0/servicePrincipals?$filter=id eq '", principalId, "'")
| invoke external_data(id:string, displayName:string) [h@graphEndpoint] with (format="json", ingestionMapping=
    @"[{""Column"":""id"",""Properties"":{""Path"":""$.value[0].id""}},
      {""Column"":""displayName"",""Properties"":{""Path"":""$.value[0].displayName""}}]"
)

3. 封装为自定义函数复用

将查询逻辑封装为自定义函数,方便重复调用:

.create function get_aad_service_principal(principalId:string)
{
    external_data(id:string, displayName:string, appId:string)
    [h@strcat("https://graph.microsoft.com/v1.0/servicePrincipals?$filter=id eq '", principalId, "'")]
    with (format = "json", ingestionMapping = 
        @"[{""Column"":""id"",""Properties"":{""Path"":""$.value[0].id""}},
          {""Column"":""displayName"",""Properties"":{""Path"":""$.value[0].displayName""}},
          {""Column"":""appId"",""Properties"":{""Path"":""$.value[0].appId""}}]"
    )
}

// 调用示例
get_aad_service_principal("<目标GUID>")

三、注意事项

  • 权限要求:执行查询的ADX主体需在AAD中拥有读取服务主体/用户的权限,否则Graph API会返回权限不足错误。
  • 性能限制:外部数据查询存在网络延迟,批量查询时需控制并发量,避免触发Graph API的速率限制。
  • 格式匹配:需确保ingestionMapping的路径与Graph API返回的JSON结构一致,避免解析失败。

内容的提问来源于stack exchange,提问作者Peter Vandivier

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 10:16:02