如何通过PowerShell获取Azure B2C中用户的注册邮箱地址?
解决Azure B2C租户中获取用户注册邮箱的问题
问题原因
Azure B2C中使用个人邮箱注册的用户,其注册邮箱并非存储在常规的Mail、ProxyAddresses等字段中,而是保存在用户对象的Identities属性内;同时Az模块的Get-AzADUser默认不会返回全部属性,导致你看到大部分字段为空。
解决方案
方案1:调整现有Az模块脚本
修改脚本以获取Identities属性,并从中提取注册邮箱:
Import-Module Az.Resources Connect-AzAccount -TenantId c4722b70-7f86-496e-a51f-f83dea9XXXXX # 获取包含Identities属性的用户对象 $Users = Get-AzADUser -All $true | Select-Object Id, DisplayName, Identities ForEach ($User in $Users) { # 筛选出signInType为emailAddress的身份条目 $emailIdentity = $User.Identities | Where-Object { $_.SignInType -eq "emailAddress" } if ($emailIdentity) { Write-Host "用户: $($User.DisplayName),注册邮箱: $($emailIdentity.IssuerAssignedId)" } else { Write-Host "用户: $($User.DisplayName),未找到邮箱身份" } }
方案2:使用Microsoft Graph PowerShell模块(推荐)
Microsoft Graph模块对Azure B2C用户属性的支持更完善,步骤如下:
- 安装模块(首次使用):
Install-Module Microsoft.Graph.Users -Force -AllowClobber
- 连接到租户并获取用户:
# 连接到Graph,需要User.Read.All权限 Connect-MgGraph -TenantId "c4722b70-7f86-496e-a51f-f83dea9XXXXX" -Scopes "User.Read.All" # 获取用户及Identities属性 $Users = Get-MgUser -All $true -Property Id, DisplayName, Identities ForEach ($User in $Users) { $emailIdentity = $User.Identities | Where-Object { $_.SignInType -eq "emailAddress" } if ($emailIdentity) { Write-Host "用户: $($User.DisplayName),注册邮箱: $($emailIdentity.IssuerAssignedId)" } }
补充说明
- Azure B2C中,
UserPrincipalName显示为GUID+onmicrosoft.com是正常现象,这是B2C系统生成的内部标识,并非用户的注册邮箱。 - 若需要将注册邮箱同步到
Mail字段,需在用户流中配置相应的属性映射规则。
内容的提问来源于stack exchange,提问作者Gojira
相关产品推荐
相关产品推荐

