如何使用Azure SDK for .NET Core列出角色分配(Role Assignment)的成员?SDK类定位及应用授权场景咨询
Hey there! I’ve been working with Azure SDK for .NET Core on authorization tasks recently, so I can help point you in the right direction here.
First off, you’ll want to use the Azure.ResourceManager.Authorization NuGet package (the modern, recommended SDK for Azure resource management) instead of the older Microsoft.Azure.Management.Authorization package. This newer SDK uses the ArmClient pattern which is more consistent across Azure services.
Step 1: Install the required package
First, add the package to your project via NuGet:
Install-Package Azure.ResourceManager.Authorization
Or via .NET CLI:
dotnet add package Azure.ResourceManager.Authorization
Step 2: Retrieve role assignments and extract member IDs
With the package installed, you can use ArmClient to fetch role assignments at the subscription, resource group, or specific resource level. Each role assignment includes a PrincipalId—this is the unique ID of the user, group, or service principal assigned to the role.
Here’s a quick example to list all role assignments for a subscription:
using Azure.Identity; using Azure.ResourceManager; using Azure.ResourceManager.Authorization; var credential = new DefaultAzureCredential(); var armClient = new ArmClient(credential); // Replace with your subscription ID var subscriptionId = "your-subscription-guid-here"; var subscriptionResource = armClient.GetSubscriptionResource( new ResourceIdentifier($"/subscriptions/{subscriptionId}") ); // Get all role assignments for the subscription await foreach (var roleAssignment in subscriptionResource.GetRoleAssignments().GetAllAsync()) { var assignmentData = roleAssignment.Data; Console.WriteLine($"Principal ID: {assignmentData.PrincipalId}"); Console.WriteLine($"Assigned Role ID: {assignmentData.RoleDefinitionId}"); Console.WriteLine($"Scope: {assignmentData.Scope}\n"); }
Step 3: Get detailed member information (optional but useful for authorization)
The PrincipalId alone might not be enough for your user authorization logic—you’ll probably want details like the user’s name, email, or group memberships. For that, you’ll need to use the Microsoft Graph SDK (since Azure Resource Manager doesn’t store directory-specific user data).
Add the Microsoft Graph package:
dotnet add package Microsoft.Graph
Then, you can fetch the user/group details using the PrincipalId:
using Microsoft.Graph; var graphClient = new GraphServiceClient(credential); // For users var user = await graphClient.Users[assignmentData.PrincipalId.ToString()].GetAsync(); Console.WriteLine($"User Name: {user.DisplayName}, Email: {user.Mail}"); // For groups var group = await graphClient.Groups[assignmentData.PrincipalId.ToString()].GetAsync(); Console.WriteLine($"Group Name: {group.DisplayName}");
Key Notes
- Permissions: Make sure your service principal or user account has the
Microsoft.Authorization/roleAssignments/readpermission (the Reader role or higher will cover this, or a custom role with this specific permission). - Scoped Assignments: If you need role assignments for a specific resource group or resource, just replace the
subscriptionResourcewith aResourceGroupResourceor the specific resource type (e.g.,VirtualMachineResource) and callGetRoleAssignments()on that instead.
This approach should give you all the data you need to build your application’s user authorization logic. Let me know if you run into any specific snags!
内容的提问来源于stack exchange,提问作者Nathan

