请求提供PowerShell脚本:导出Azure AD所有资源组的RBAC至单个CSV
PowerShell脚本导出所有资源组的角色分配
以下脚本会遍历当前订阅下的所有资源组,导出每个资源组内所有资源的角色分配,并保存为CSV文件:
# 连接到Azure账户 Connect-AzAccount # 获取当前订阅下的所有资源组 $resourceGroups = Get-AzResourceGroup # 初始化数组存储角色分配数据 $roleAssignments = @() # 遍历每个资源组 foreach ($rg in $resourceGroups) { Write-Host "正在处理资源组: $($rg.ResourceGroupName)" # 获取资源组内的所有资源 $resources = Get-AzResource -ResourceGroupName $rg.ResourceGroupName # 遍历每个资源 foreach ($resource in $resources) { # 获取该资源的角色分配 $assignments = Get-AzRoleAssignment -Scope $resource.ResourceId # 整理数据并添加到数组 foreach ($assignment in $assignments) { $roleAssignments += [PSCustomObject]@{ ResourceGroupName = $rg.ResourceGroupName ResourceName = $resource.Name ResourceType = $resource.ResourceType RoleDefinitionName = $assignment.RoleDefinitionName PrincipalName = $assignment.PrincipalName PrincipalType = $assignment.PrincipalType AssignmentScope = $assignment.Scope CreatedOn = $assignment.CreatedOn } } } } # 导出到CSV文件 $outputPath = "AzureResourceRoleAssignments_$(Get-Date -Format 'yyyyMMdd_HHmmss').csv" $roleAssignments | Export-Csv -Path $outputPath -NoTypeInformation -Encoding UTF8 Write-Host "导出完成,文件路径: $outputPath"
关键说明
- 运行前确保已安装
Az.Resources模块:未安装则执行Install-Module -Name Az.Resources -Force -AllowClobber - 若已有Azure会话,可注释掉
Connect-AzAccount行 - 导出的CSV包含资源组名称、资源基本信息、角色分配主体及分配时间等核心字段
- 需指定特定订阅时,在
Connect-AzAccount后添加Set-AzContext -SubscriptionId "你的订阅ID"
内容的提问来源于stack exchange,提问作者user1628
相关产品推荐
相关产品推荐

