You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD按周期自动禁用非活跃用户的技术方案问询

自动禁用Azure AD非活跃用户(区分标准/管理员账户)

需求说明

  • 标准用户90天未登录时自动禁用
  • 管理员用户30天未登录时自动禁用
  • 可选:给被自动禁用的用户发送邮件通知
  • 已具备MS Graph访问权限和Azure全局管理员权限

试过Identity Governance仅支持自动禁用来宾账户,现有示例脚本不符合需求且运行失败,以下是适配需求的解决方案。

解决方案:PowerShell脚本(基于MS Graph API)

前置准备

  1. 确保已安装Microsoft.Graph模块:
Install-Module -Name Microsoft.Graph -Force -AllowClobber
  1. 配置所需的MS Graph应用权限:
    • User.Read.All(读取所有用户信息)
    • Directory.Read.All(读取目录角色)
    • User.ReadWrite.All(修改用户状态)
    • Mail.Send(可选,发送邮件通知)

完整脚本

# 连接MS Graph(使用全局管理员账户或服务主体)
Connect-MgGraph -Scopes "User.Read.All","Directory.Read.All","User.ReadWrite.All","Mail.Send"

# 定义禁用阈值
$standardUserInactiveDays = 90
$adminUserInactiveDays = 30
$today = Get-Date

# 获取所有用户及其最后登录信息、目录角色
$users = Get-MgUser -All -Property DisplayName, UserPrincipalName, SignInActivity, Id | ForEach-Object {
    # 获取用户的目录角色(判断是否为管理员)
    $roles = Get-MgUserMemberOf -UserId $_.Id | Where-Object { $_.AdditionalProperties.'@odata.type' -eq '#microsoft.graph.directoryRole' }
    $isAdmin = $roles.Count -gt 0 -and $roles.AdditionalProperties.displayName -match "全局管理员|Exchange管理员|SharePoint管理员" # 可按需调整管理员角色列表
    
    [PSCustomObject]@{
        DisplayName         = $_.DisplayName
        UserPrincipalName   = $_.UserPrincipalName
        Id                  = $_.Id
        LastSignInDateTime  = if ($_.SignInActivity.LastSignInDateTime) { [datetime]$_.SignInActivity.LastSignInDateTime } else { $null }
        IsAdmin             = $isAdmin
    }
}

# 处理非活跃用户
foreach ($user in $users) {
    # 跳过从未登录过的用户(可按需调整)
    if (-not $user.LastSignInDateTime) {
        Write-Host "跳过从未登录的用户:$($user.UserPrincipalName)"
        continue
    }

    $daysInactive = ($today - $user.LastSignInDateTime).Days
    $threshold = if ($user.IsAdmin) { $adminUserInactiveDays } else { $standardUserInactiveDays }

    if ($daysInactive -gt $threshold) {
        Write-Host "禁用非活跃用户:$($user.UserPrincipalName),最后登录:$($user.LastSignInDateTime),已闲置$daysInactive天"
        
        # 禁用用户账户
        Update-MgUser -UserId $user.Id -AccountEnabled:$false
        # 撤销用户所有刷新令牌
        Revoke-MgUserRefreshToken -UserId $user.Id

        # 发送邮件通知(可选)
        try {
            $mailBody = @"
<p>您好,$($user.DisplayName):</p>
<p>您的Azure AD账户因超过$threshold天未登录,已被自动禁用。</p>
<p>如需恢复账户,请联系IT管理员。</p>
"@
            Send-MgUserMail -UserId $user.Id -MessageParameter @{
                Subject = "您的Azure AD账户已被自动禁用"
                Body = @{
                    ContentType = "HTML"
                    Content = $mailBody
                }
                ToRecipients = @(@{
                    EmailAddress = @{
                        Address = $user.UserPrincipalName
                    }
                })
            }
            Write-Host "已向$($user.UserPrincipalName)发送禁用通知邮件"
        }
        catch {
            Write-Warning "发送邮件失败:$($_.Exception.Message)"
        }
    }
    else {
        Write-Host "用户$($user.UserPrincipalName)处于活跃状态,最后登录:$($user.LastSignInDateTime),已闲置$daysInactive天"
    }
}

# 断开MS Graph连接
Disconnect-MgGraph

脚本关键说明

  1. 管理员识别:通过检查用户是否属于指定目录角色(如全局管理员、Exchange管理员等),可根据实际需求修改角色匹配规则。
  2. 阈值设置:分别为标准用户和管理员用户定义不同的闲置天数阈值。
  3. 邮件通知:使用MS Graph的Send-MgUserMail接口发送HTML格式通知邮件,需提前配置Mail.Send权限。
  4. 批量处理:通过Get-MgUser -All获取所有用户,自动处理分页结果。

自动化部署(可选)

可将此脚本部署到Azure Automation Runbook,设置定期执行计划(如每周一次),实现完全自动化的非活跃用户管理。

内容的提问来源于stack exchange,提问作者TheDen88

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 23:09:55