You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用PowerShell提取AzureAD动态组成员规则?脚本规则列空白

Azure AD动态组MembershipRule返回为空的解决方法
  • 权限验证:
    读取动态组成员规则需要Azure AD Premium P1/P2许可证,且你的账户需具备Group.Read.All或Directory.Read.All权限(应用权限优先,委派权限需确保上下文正确)。

  • 命令调整:
    部分场景下Select-Object可能无法正确映射属性,可尝试用循环提取属性值:

    Get-AzureADMSGroup -Filter "groupTypes/any(c:c eq 'DynamicMembership')" -All:$true | ForEach-Object {
        [PSCustomObject]@{
            DisplayName = $_.DisplayName
            MembershipRule = $_.MembershipRule
        }
    }
    

    同时确认目标动态组确实配置了成员规则——部分动态组可能因创建方式或后续操作导致规则被清空。

  • 切换到Microsoft Graph模块:
    AzureAD模块已逐步被Microsoft Graph PowerShell替代,使用以下命令可更稳定地获取属性:

    Connect-MgGraph -Scopes "Group.Read.All"
    Get-MgGroup -Filter "groupTypes/any(c:c eq 'DynamicMembership')" -All -Property DisplayName,MembershipRule | Select-Object DisplayName,MembershipRule
    

内容的提问来源于stack exchange,提问作者TMI

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 13:59:53