使用Get-MgGroup筛选本地组:CreatedDateTime筛选失效,字段类型一致
用Get-MgGroup筛选CreatedDateTime报错,但OnPremisesLastSyncDateTime正常的问题
我在使用Microsoft Graph的Get-MgGroup命令筛选过去24小时创建的本地组时遇到了一个问题:虽然OnPremisesLastSyncDateTime和CreatedDateTime都是DateTime类型,但前者作为筛选条件能正常返回结果,后者却直接报错。
我的代码
$now = Get-Date # 减去24小时 $Time = $now.AddHours(-24) # 转换为ISO 8601格式 $TimeISO = $Time.ToString("yyyy-MM-ddTHH:mm:ssZ") $X = Get-MgGroup -Filter "OnPremisesLastSyncDateTime ge $TimeISO"| fl $Y= Get-MgGroup -Filter "CreatedDateTime ge $TimeISO"| fl
报错信息
PS C:\WINDOWS\system32> Get-MgGroup -Filter "CreatedDateTime ge $TimeISO"| fl Get-MgGroup : Unsupported or invalid query filter clause specified for property 'createdDateTime' of resource 'Group'. At line:1 char:1 + Get-MgGroup -Filter "CreatedDateTime ge $TimeISO"| fl + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : InvalidOperation: ({ ConsistencyLe...ndProperty = }:<>f__Anonym ousType84`9) [Get-MgGroup_List], RestException`1 + FullyQualifiedErrorId : Request_UnsupportedQuery,Microsoft.Graph.PowerShell.Cmdlets.GetM gGroup_List PS C:\WINDOWS\system32> $X = Get-MgGroup -Filter "OnPremisesLastSyncDateTime ge $TimeISO" PS C:\WINDOWS\system32> $X.OnPremisesLastSyncDateTime.GetType() $X.CreatedDateTime.GetType() IsPublic IsSerial Name BaseType -------- -------- ---- -------- True True DateTime System.ValueType True True DateTime System.ValueType PS C:\WINDOWS\system32> $TimeISO 2023-07-26T17:04:29Z
原因分析
核心问题是Microsoft Graph的Group资源中,createdDateTime属性不支持$filter查询,而onPremisesLastSyncDateTime是官方明确支持筛选的属性。两者虽然在返回结果里都是DateTime类型,但Graph API对不同属性的查询支持取决于后端是否为该属性建立了可筛选索引,和属性本身的数据类型无关。
解决方案
方案1:本地筛选(适合组数量不多的场景)
先拉取所有组,再在PowerShell本地用Where-Object过滤创建时间:
$now = Get-Date $time24HoursAgo = $now.AddHours(-24) # 拉取所有组 $allGroups = Get-MgGroup -All # 本地筛选过去24小时创建的组 $recentCreatedGroups = $allGroups | Where-Object { $_.CreatedDateTime -ge $time24HoursAgo } | Format-List
方案2:Delta查询(适合长期跟踪新增组的场景)
用Graph的Delta查询增量获取组的变化,避免全量拉取:
$now = Get-Date $time24HoursAgo = $now.AddHours(-24) # 首次运行获取delta链接(保存下来后续复用) $deltaResult = Get-MgGroup -Delta $deltaLink = $deltaResult.'@odata.deltaLink' # 后续运行用delta链接获取新增/修改的组,再筛选创建时间 $deltaGroups = Invoke-MgGraphRequest -Uri $deltaLink -Method Get $recentCreatedGroups = $deltaGroups.value | Where-Object { [DateTime]$_.createdDateTime -ge $time24HoursAgo }
内容的提问来源于stack exchange,提问作者A sahn
相关产品推荐
相关产品推荐

