You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

导出关联用户/组及所有者的Azure AD IDP企业应用问题

导出Azure AD IDP企业应用的关联用户、组及所有者

问题说明

现有PowerShell脚本通过Get-AzureADServiceAppRoleAssignment仅能获取应用关联的用户和组(对应PrincipalType为User/Group),但无法获取应用所有者——因为所有者信息并不在应用角色分配结果中,需通过专门的命令获取。同时需要确保即使应用未分配所有者或无用户/组关联,也能在报表中显示该应用。

解决方案脚本

以下脚本整合了应用所有者、用户/组分配的获取逻辑,同时处理空数据场景:

# 初始化结果存储数组
$reportResults = @()
$date = Get-Date -Format "yyyyMMdd"

# 遍历所有目标企业应用服务主体
foreach ($servicePrincipal in $ServicePrincipalList) {
    $appDisplayName = $servicePrincipal.DisplayName
    $appObjectId = $servicePrincipal.ObjectId

    # 获取应用所有者信息
    $appOwners = Get-AzureADServicePrincipalOwner -ObjectId $appObjectId -ErrorAction SilentlyContinue

    # 处理所有者条目:无所有者时生成占位记录
    if ($appOwners) {
        foreach ($owner in $appOwners) {
            $reportResults += [PSCustomObject]@{
                ResourceDisplayName  = $appDisplayName
                ResourceId           = $appObjectId
                PrincipalDisplayName = $owner.DisplayName
                PrincipalType        = "Owner"
                PrincipalId          = $owner.ObjectId
            }
        }
    } else {
        $reportResults += [PSCustomObject]@{
            ResourceDisplayName  = $appDisplayName
            ResourceId           = $appObjectId
            PrincipalDisplayName = "无所有者"
            PrincipalType        = "Owner"
            PrincipalId          = $null
        }
    }

    # 获取应用的用户/组分配信息
    $appAssignments = Get-AzureADServiceAppRoleAssignment -ObjectId $appObjectId -ErrorAction SilentlyContinue

    # 处理用户/组分配条目:无分配时生成占位记录
    if ($appAssignments) {
        foreach ($assignment in $appAssignments) {
            $reportResults += [PSCustomObject]@{
                ResourceDisplayName  = $assignment.ResourceDisplayName
                ResourceId           = $assignment.ResourceId
                PrincipalDisplayName = $assignment.PrincipalDisplayName
                PrincipalType        = $assignment.PrincipalType
                PrincipalId          = $assignment.PrincipalId
            }
        }
    } else {
        $reportResults += [PSCustomObject]@{
            ResourceDisplayName  = $appDisplayName
            ResourceId           = $appObjectId
            PrincipalDisplayName = "无用户/组分配"
            PrincipalType        = $null
            PrincipalId          = $null
        }
    }
}

# 导出最终报表到CSV
$reportResults | Export-Csv -Path "C:\PSReports\AzureAD_IDP_Apps - $date.csv" -NoTypeInformation -Encoding UTF8

关键逻辑说明

  • 所有者获取:通过Get-AzureADServicePrincipalOwner命令单独拉取应用所有者,手动指定PrincipalType为Owner(原命令无该字段)
  • 空数据处理:添加-ErrorAction SilentlyContinue避免无数据时报错,同时生成占位记录确保每个应用都能出现在报表中
  • 性能优化:先将所有数据存入数组,最后一次性导出CSV,避免多次Append操作导致的性能损耗

内容的提问来源于stack exchange,提问作者bacjac38

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 05:12:33