如何使用PowerShell导出Azure资源配置及IP白名单配置至CSV文件?
Absolutely! You can absolutely export Azure resource configurations—including IP whitelisting rules—to a CSV using PowerShell. Let me walk you through exactly how to do this, covering both general resource configs and targeted IP whitelist exports.
Prerequisites
First, make sure you have the Azure PowerShell module set up and you're logged into your account:
# Install Azure PowerShell if you haven't already Install-Module -Name Az -Scope CurrentUser -Repository PSGallery -Force # Log into your Azure account Connect-AzAccount # If you have multiple subscriptions, set the correct one Set-AzContext -SubscriptionId "your-subscription-id"
Exporting General Resource Configurations
To get a broad overview of your Azure resources and their core details, use this script to pull key configurations and export them to CSV:
# Retrieve all resources in your subscription (filter with -ResourceGroupName if needed) $resourceConfigs = Get-AzResource | Select-Object ` Name, ResourceType, Location, ResourceGroupName, Id, Tags # Export to CSV (adjust the path to your preferred location) $resourceConfigs | Export-Csv -Path "C:\Azure_Resource_Configs.csv" -NoTypeInformation -Encoding UTF8
This gives you a clean CSV with basics like resource names, types, locations, and tags.
Exporting IP Whitelisting Configurations
IP whitelisting lives in different places depending on the Azure resource type—let's cover the most common ones:
1. App Service (Web Apps/Function Apps) Access Restrictions
Web Apps use access restriction rules to allow specific IPs. Extract these with:
# Target a specific web app $webAppRestrictions = Get-AzWebAppAccessRestrictionConfig ` -ResourceGroupName "your-resource-group-name" ` -Name "your-web-app-name" # Filter for allow rules (IP whitelist entries) $ipWhitelistRules = $webAppRestrictions.MainSiteAccessRestrictions | Where-Object { $_.Action -eq "Allow" -and $_.IpAddress -ne $null } | Select-Object Name, IpAddress, Priority, Action # Export to CSV $ipWhitelistRules | Export-Csv -Path "C:\WebApp_IP_Whitelist.csv" -NoTypeInformation -Encoding UTF8
2. Network Security Groups (NSGs)
NSGs control traffic to VMs and other resources—extract allow rules targeting specific IPs:
# Target a specific NSG $nsg = Get-AzNetworkSecurityGroup ` -ResourceGroupName "your-resource-group-name" ` -Name "your-nsg-name" # Filter inbound allow rules (exclude service tags if you only want explicit IPs) $nsgWhitelist = $nsg.SecurityRules | Where-Object { $_.Access -eq "Allow" -and $_.SourceAddressPrefix -notlike "*ServiceTag*" } | Select-Object Name, Direction, Access, SourceAddressPrefix, DestinationPortRange, Priority # Export to CSV $nsgWhitelist | Export-Csv -Path "C:\NSG_IP_Whitelist.csv" -NoTypeInformation -Encoding UTF8
3. Storage Account Firewall Rules
Storage accounts use firewall rules to restrict access to specific IP ranges:
# Target a specific storage account $storageAccount = Get-AzStorageAccount ` -ResourceGroupName "your-resource-group-name" ` -Name "your-storage-account-name" # Extract IP allow rules $storageWhitelist = $storageAccount.NetworkRuleSet.IpRules | Select-Object Value, Action # Export to CSV $storageWhitelist | Export-Csv -Path "C:\Storage_IP_Whitelist.csv" -NoTypeInformation -Encoding UTF8
Combine Multiple IP Whitelists into One CSV
If you want a single CSV with all your IP whitelist rules across resource types, use this approach to aggregate data:
# Initialize an empty array to hold all rules $allWhitelistRules = @() # Add Web App rules $webAppRules = Get-AzWebAppAccessRestrictionConfig -ResourceGroupName "rg-prod" -Name "webapp-prod" | ForEach-Object { $_.MainSiteAccessRestrictions | Where-Object { $_.Action -eq "Allow" -and $_.IpAddress -ne $null } | Select-Object ` @{Name="ResourceName"; Expression={"webapp-prod"}}, @{Name="ResourceType"; Expression="Web App"}, @{Name="RuleName"; Expression={$_.Name}}, @{Name="IPAddress"; Expression={$_.IpAddress}}, @{Name="Priority"; Expression={$_.Priority}} } $allWhitelistRules += $webAppRules # Add NSG rules $nsgRules = Get-AzNetworkSecurityGroup -ResourceGroupName "rg-prod" -Name "nsg-vms" | ForEach-Object { $_.SecurityRules | Where-Object { $_.Access -eq "Allow" -and $_.SourceAddressPrefix -notlike "*ServiceTag*" } | Select-Object ` @{Name="ResourceName"; Expression={"nsg-vms"}}, @{Name="ResourceType"; Expression="Network Security Group"}, @{Name="RuleName"; Expression={$_.Name}}, @{Name="IPAddress"; Expression={$_.SourceAddressPrefix}}, @{Name="Priority"; Expression={$_.Priority}} } $allWhitelistRules += $nsgRules # Add Storage Account rules $storageRules = Get-AzStorageAccount -ResourceGroupName "rg-prod" -Name "storageprod" | ForEach-Object { $_.NetworkRuleSet.IpRules | Select-Object ` @{Name="ResourceName"; Expression={"storageprod"}}, @{Name="ResourceType"; Expression="Storage Account"}, @{Name="RuleName"; Expression="Firewall Allow Rule"}, @{Name="IPAddress"; Expression={$_.Value}}, @{Name="Priority"; Expression=$null} } $allWhitelistRules += $storageRules # Export combined rules to CSV $allWhitelistRules | Export-Csv -Path "C:\All_Azure_IP_Whitelists.csv" -NoTypeInformation -Encoding UTF8
Quick Notes
- Permissions: Make sure your Azure account has at least Reader access to the resources you're exporting.
- Batch Processing: To scale this to multiple resources, wrap the commands in a
foreachloop (e.g., loop through all Web Apps in a resource group). - Customization: Adjust the
Select-Objectproperties to include any additional fields you need (like resource IDs or rule descriptions).
内容的提问来源于stack exchange,提问作者Dazure

