Azure AD按周期自动禁用非活跃用户的技术方案问询
自动禁用Azure AD非活跃用户(区分标准/管理员账户)
需求说明
- 标准用户90天未登录时自动禁用
- 管理员用户30天未登录时自动禁用
- 可选:给被自动禁用的用户发送邮件通知
- 已具备MS Graph访问权限和Azure全局管理员权限
试过Identity Governance仅支持自动禁用来宾账户,现有示例脚本不符合需求且运行失败,以下是适配需求的解决方案。
解决方案:PowerShell脚本(基于MS Graph API)
前置准备
- 确保已安装
Microsoft.Graph模块:
Install-Module -Name Microsoft.Graph -Force -AllowClobber
- 配置所需的MS Graph应用权限:
User.Read.All(读取所有用户信息)Directory.Read.All(读取目录角色)User.ReadWrite.All(修改用户状态)Mail.Send(可选,发送邮件通知)
完整脚本
# 连接MS Graph(使用全局管理员账户或服务主体) Connect-MgGraph -Scopes "User.Read.All","Directory.Read.All","User.ReadWrite.All","Mail.Send" # 定义禁用阈值 $standardUserInactiveDays = 90 $adminUserInactiveDays = 30 $today = Get-Date # 获取所有用户及其最后登录信息、目录角色 $users = Get-MgUser -All -Property DisplayName, UserPrincipalName, SignInActivity, Id | ForEach-Object { # 获取用户的目录角色(判断是否为管理员) $roles = Get-MgUserMemberOf -UserId $_.Id | Where-Object { $_.AdditionalProperties.'@odata.type' -eq '#microsoft.graph.directoryRole' } $isAdmin = $roles.Count -gt 0 -and $roles.AdditionalProperties.displayName -match "全局管理员|Exchange管理员|SharePoint管理员" # 可按需调整管理员角色列表 [PSCustomObject]@{ DisplayName = $_.DisplayName UserPrincipalName = $_.UserPrincipalName Id = $_.Id LastSignInDateTime = if ($_.SignInActivity.LastSignInDateTime) { [datetime]$_.SignInActivity.LastSignInDateTime } else { $null } IsAdmin = $isAdmin } } # 处理非活跃用户 foreach ($user in $users) { # 跳过从未登录过的用户(可按需调整) if (-not $user.LastSignInDateTime) { Write-Host "跳过从未登录的用户:$($user.UserPrincipalName)" continue } $daysInactive = ($today - $user.LastSignInDateTime).Days $threshold = if ($user.IsAdmin) { $adminUserInactiveDays } else { $standardUserInactiveDays } if ($daysInactive -gt $threshold) { Write-Host "禁用非活跃用户:$($user.UserPrincipalName),最后登录:$($user.LastSignInDateTime),已闲置$daysInactive天" # 禁用用户账户 Update-MgUser -UserId $user.Id -AccountEnabled:$false # 撤销用户所有刷新令牌 Revoke-MgUserRefreshToken -UserId $user.Id # 发送邮件通知(可选) try { $mailBody = @" <p>您好,$($user.DisplayName):</p> <p>您的Azure AD账户因超过$threshold天未登录,已被自动禁用。</p> <p>如需恢复账户,请联系IT管理员。</p> "@ Send-MgUserMail -UserId $user.Id -MessageParameter @{ Subject = "您的Azure AD账户已被自动禁用" Body = @{ ContentType = "HTML" Content = $mailBody } ToRecipients = @(@{ EmailAddress = @{ Address = $user.UserPrincipalName } }) } Write-Host "已向$($user.UserPrincipalName)发送禁用通知邮件" } catch { Write-Warning "发送邮件失败:$($_.Exception.Message)" } } else { Write-Host "用户$($user.UserPrincipalName)处于活跃状态,最后登录:$($user.LastSignInDateTime),已闲置$daysInactive天" } } # 断开MS Graph连接 Disconnect-MgGraph
脚本关键说明
- 管理员识别:通过检查用户是否属于指定目录角色(如全局管理员、Exchange管理员等),可根据实际需求修改角色匹配规则。
- 阈值设置:分别为标准用户和管理员用户定义不同的闲置天数阈值。
- 邮件通知:使用MS Graph的
Send-MgUserMail接口发送HTML格式通知邮件,需提前配置Mail.Send权限。 - 批量处理:通过
Get-MgUser -All获取所有用户,自动处理分页结果。
自动化部署(可选)
可将此脚本部署到Azure Automation Runbook,设置定期执行计划(如每周一次),实现完全自动化的非活跃用户管理。
内容的提问来源于stack exchange,提问作者TheDen88
相关产品推荐
相关产品推荐

