You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何获取特定用户所属条件访问策略组及关联策略(MsolService模块)

关于条件访问策略与用户关联的PowerShell查询方案

1. 获取特定用户所属的所有条件访问策略组的列表

要实现这个需求,需先定位用户所属的所有安全组/Office 365组,再遍历所有条件访问策略,筛选出包含这些组的策略。推荐使用Microsoft Graph PowerShell模块(功能全面且为微软主推的新版模块),操作步骤如下:

  • 安装并连接Microsoft Graph:

    Install-Module Microsoft.Graph.Identity.SignIns -Force
    Connect-MgGraph -Scopes "Policy.Read.All", "GroupMember.Read.All"
    
  • 获取目标用户的所有所属组ID:

    $userId = "目标用户的UPN或ObjectID"
    $userGroups = Get-MgUserMemberOf -UserId $userId | Select-Object Id
    
  • 获取所有条件访问策略,筛选出包含用户所属组的策略:

    $allConditionalAccessPolicies = Get-MgIdentityConditionalAccessPolicy
    $userRelatedPolicies = $allConditionalAccessPolicies | Where-Object {
        # 检查策略的包含组是否有用户所属的组
        $_.Conditions.Users.IncludeGroups -and ($_.Conditions.Users.IncludeGroups | Where-Object { $_ -in $userGroups.Id })
        # 若需同时检查排除组,可追加:-or $_.Conditions.Users.ExcludeGroups | Where-Object { $_ -in $userGroups.Id }
    }
    
  • 输出结果(包含策略名称和关联组信息):

    $userRelatedPolicies | Select-Object DisplayName, @{Name="IncludedGroups"; Expression={$_.Conditions.Users.IncludeGroups}}
    

2. 能否通过MsolService模块获取与特定用户关联的所有条件访问策略?

不行。MsolService模块(旧版Azure AD PowerShell模块) 不支持查询条件访问策略相关数据,该模块仅用于管理用户、组、许可证等基础Azure AD对象,没有针对条件访问策略的Cmdlet。

若要查询条件访问策略,需使用AzureAD模块(旧版但仍可用)或Microsoft Graph PowerShell模块(推荐,符合微软未来API迭代方向)。以下是AzureAD模块的示例代码:

Install-Module AzureAD -Force
Connect-AzureAD
$userId = "目标用户的UPN或ObjectID"
$userGroups = Get-AzureADUserMembership -ObjectId $userId | Select-Object ObjectId
$allCAPolicies = Get-AzureADMSConditionalAccessPolicy
$userRelatedPolicies = $allCAPolicies | Where-Object {
    $_.Conditions.Users.IncludeGroups -and ($_.Conditions.Users.IncludeGroups | Where-Object { $_ -in $userGroups.ObjectId })
}
$userRelatedPolicies | Select-Object DisplayName, Conditions

内容的提问来源于stack exchange,提问作者RishV

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 15:04:59