You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD动态组创建求助:职位筛选规则与参数错误问题

问题解决

错误原因

  • 参数名称错误:New-AzureADMSGroup cmdlet 不存在MembershipRuleEvaluationType和MembershipRuleFilterType这两个参数,动态组类型需要通过GroupTypes参数指定为"DynamicMembership"。
  • 成员规则语法错误:Azure AD动态组的成员规则使用特定查询语法(非PowerShell表达式),需用contains等操作符,属性引用格式为user.jobTitle而非user.[JobTitle]。

修正后的脚本

$groupName = "DynamicManagersGroup"
$groupDescription = "Dynamic Group for Managers"
$includedJobTitles = @("Manager", "Director")
$excludedJobTitles = @("Case Manager", "Lead Case Manager", "Housing Case Manager")

# 构建包含规则:职位包含Manager或Director
$includedClauses = $includedJobTitles | ForEach-Object { "user.jobTitle contains '$_'" }
$includedExpression = $includedClauses -join " or "

# 构建排除规则:排除指定的Case Manager类职位
$excludedClauses = $excludedJobTitles | ForEach-Object { "user.jobTitle contains '$_'" }
$excludedExpression = $excludedClauses -join " or "

# 组合最终的成员规则
$dynamicMembershipRules = "($includedExpression) and not ($excludedExpression)"

# 创建动态组
New-AzureADMSGroup -DisplayName $groupName `
                   -Description $groupDescription `
                   -GroupTypes "DynamicMembership" `
                   -MembershipRule $dynamicMembershipRules `
                   -SecurityEnabled $true `
                   -MailEnabled $false `
                   -MailNickName "dynamicmanagersgroup"

关键修改说明

  1. 参数修正:移除错误参数,添加GroupTypes "DynamicMembership"指定动态组类型。
  2. 规则语法修正:
    • 使用Azure AD动态组支持的语法,属性引用为user.jobTitle(小写属性名)。
    • 用contains操作符匹配职位关键词,or连接多条件,and not实现排除逻辑。
  3. 必填参数补充:添加SecurityEnabled、MailEnabled和MailNickName等必填参数,不需要邮件功能时设置MailEnabled $false即可。

内容的提问来源于stack exchange,提问作者Don Blake

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 11:52:41