You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure PowerShell脚本报错:Scope '/subscriptions'部分数量需为偶数

解决Azure PowerShell脚本报错:Scope '/subscriptions' should have even number of parts

错误原因

脚本中使用了未定义的全局变量$global:SourceSubscription,导致拼接后的Scope仅为/subscriptions/(实际为空值,最终变成/subscriptions),不符合Azure资源Scope的规范格式。Azure订阅级Scope必须是/subscriptions/{订阅ID}的结构,部分数量为偶数(2个部分:subscriptions和具体的订阅ID),缺失订阅ID会导致部分数为奇数,触发该错误。

修正步骤

  • 替换未定义变量:把$global:SourceSubscription替换为脚本开头已定义的$subscriptionId变量,确保Scope格式正确。
  • 修复换行符语法:将Write-Host中的单引号'n改为反引号`n,否则无法正确输出换行。
  • 拆分导出CSV的代码行:原脚本中注释与代码连在一起,拆分后保证代码可执行。
  • 可选优化:若已通过Connect-AzAccount指定订阅,可直接省略-Scope参数,Get-AzRoleAssignment默认会获取当前订阅的角色分配。

修正后的完整脚本

$tenantId = "xxxxxx"
$subscriptionId = "xxxxxxx"

# Log in to Azure with tenant and subscription IDs
Connect-AzAccount -Tenant $tenantId -Subscription $subscriptionId -UseDeviceAuthentication

# Role Assignment Function
Function Get-RoleAssignments(){
    Write-Host "`n> Checking IAM Role Assignments…`n" -ForegroundColor Green
    $Global:RoleAssignments = [System.Collections.ArrayList]::new()
    # 替换未定义变量为已有的$subscriptionId,或直接省略-Scope参数
    $RoleAssignment = Get-AzRoleAssignment -Scope "/subscriptions/$subscriptionId"

    foreach($role in $RoleAssignment){
        $csvObject = New-Object PSObject
        Add-Member -inputObject $csvObject -memberType NoteProperty -name "Display Name" -value $role.DisplayName
        Add-Member -inputObject $csvObject -memberType NoteProperty -name "SignIn Name" -value $role.SignInName
        Add-Member -inputObject $csvObject -memberType NoteProperty -name "Object Type" -value $role.ObjectType
        Add-Member -inputObject $csvObject -memberType NoteProperty -name "Object ID" -value $role.ObjectId
        Add-Member -inputObject $csvObject -memberType NoteProperty -name "Role" -value $role.RoleDefinitionName
        Add-Member -inputObject $csvObject -memberType NoteProperty -name "RoleDefinition ID" -value $role.RoleDefinitionId
        Add-Member -inputObject $csvObject -memberType NoteProperty -name "Scope" -value $role.Scope
        Add-Member -inputObject $csvObject -memberType NoteProperty -name "Description" -value $role.Description
        Add-Member -inputObject $csvObject -memberType NoteProperty -name "CanDelegate" -value $role.CanDelegate

        $Global:RoleAssignments.Add($csvObject) | Out-Null
    }
}

# Call the function to populate $Global:RoleAssignments
Get-RoleAssignments

# Export the collected quota information to a CSV file
$Global:RoleAssignments | Export-Csv -Path "RoleAssignment.csv" -NoTypeInformation

Write-Host "Resource report generated and saved to RoleAssignment.csv"

额外说明

  • 若需要获取多个订阅的角色分配,可定义订阅ID数组,循环遍历每个订阅并设置当前上下文后执行Get-AzRoleAssignment。
  • 使用Get-AzRoleAssignment时,不指定-Scope会默认获取当前登录上下文订阅下的所有角色分配,代码更简洁。

内容的提问来源于stack exchange,提问作者Dheeman Das

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 16:04:52