能否通过内置KQL函数或变通方法在ADX管理查询中获取服务主体详情?
在ADX中查询其他AAD主体详情的方法
一、内置函数限制说明
目前Kusto没有直接查询任意AAD主体详情的内置函数,ADX的KQL函数主要聚焦于自身权限上下文及集群/数据库的管理操作,无法直接调用AAD或Microsoft Graph接口获取外部主体信息。
二、变通方法
1. 集成Microsoft Graph API查询
通过external_data运算符调用Microsoft Graph API,可获取AAD主体的详细信息。执行此操作的主体需具备调用Graph相关接口的权限(如User.Read.All、Application.Read.All等)。
示例查询(针对服务主体):
external_data(id:string, displayName:string, appId:string, servicePrincipalType:string) [h@"https://graph.microsoft.com/v1.0/servicePrincipals?$filter=id eq '<目标AAD GUID>'"] with (format = "json", ingestionMapping = @"[{""Column"":""id"",""Properties"":{""Path"":""$.value[0].id""}}, {""Column"":""displayName"",""Properties"":{""Path"":""$.value[0].displayName""}}, {""Column"":""appId"",""Properties"":{""Path"":""$.value[0].appId""}}, {""Column"":""servicePrincipalType"",""Properties"":{""Path"":""$.value[0].servicePrincipalType""}}]" )
2. 批量处理控制命令中的主体ID
结合.show commands-and-queries提取服务主体ID,再批量调用Graph API:
// 提取命令记录中的服务主体ID .show commands-and-queries | where StartedBy startswith "app:" | parse StartedBy with "app:" principalId:string | distinct principalId // 对每个ID调用Graph API(示例为单ID扩展逻辑) | extend graphEndpoint = strcat("https://graph.microsoft.com/v1.0/servicePrincipals?$filter=id eq '", principalId, "'") | invoke external_data(id:string, displayName:string) [h@graphEndpoint] with (format="json", ingestionMapping= @"[{""Column"":""id"",""Properties"":{""Path"":""$.value[0].id""}}, {""Column"":""displayName"",""Properties"":{""Path"":""$.value[0].displayName""}}]" )
3. 封装为自定义函数复用
将查询逻辑封装为自定义函数,方便重复调用:
.create function get_aad_service_principal(principalId:string) { external_data(id:string, displayName:string, appId:string) [h@strcat("https://graph.microsoft.com/v1.0/servicePrincipals?$filter=id eq '", principalId, "'")] with (format = "json", ingestionMapping = @"[{""Column"":""id"",""Properties"":{""Path"":""$.value[0].id""}}, {""Column"":""displayName"",""Properties"":{""Path"":""$.value[0].displayName""}}, {""Column"":""appId"",""Properties"":{""Path"":""$.value[0].appId""}}]" ) } // 调用示例 get_aad_service_principal("<目标GUID>")
三、注意事项
- 权限要求:执行查询的ADX主体需在AAD中拥有读取服务主体/用户的权限,否则Graph API会返回权限不足错误。
- 性能限制:外部数据查询存在网络延迟,批量查询时需控制并发量,避免触发Graph API的速率限制。
- 格式匹配:需确保
ingestionMapping的路径与Graph API返回的JSON结构一致,避免解析失败。
内容的提问来源于stack exchange,提问作者Peter Vandivier
相关产品推荐
相关产品推荐

