You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell查询Azure AD用户启用/禁用的审计日志

获取Azure AD用户启用/禁用的审计日志(含操作时间与执行者)

你之前使用的Get-AzureADAuditSignInLogs和Get-MgAuditLogSignIn是登录行为日志,无法捕获用户账户启用/禁用这类目录操作记录。要获取目标日志,需使用目录审计日志相关命令,分两种模块说明:

一、推荐使用Microsoft Graph模块(AzureAD模块即将弃用)

1. 前置准备

先安装并连接模块:

# 首次使用时安装模块
Install-Module Microsoft.Graph -Force -AllowClobber
# 连接并申请审计日志读取权限
Connect-MgGraph -Scopes AuditLog.Read.All

2. 筛选用户启用/禁用日志

通过Filter参数精准定位目标操作,同时提取关键信息:

Get-MgAuditLogDirectoryAudit -Filter "createdDateTime ge 2023-05-29T00:00:00Z and createdDateTime le 2023-06-03T00:00:00Z and (activityDisplayName eq 'Disable user account' or activityDisplayName eq 'Enable user account')" | 
Select-Object CreatedDateTime,
              @{Name='执行者'; Expression={$_.InitiatedBy.User.UserPrincipalName}},
              @{Name='目标用户'; Expression={$_.TargetResources[0].UserPrincipalName}},
              ActivityDisplayName

字段说明:

  • CreatedDateTime:操作发生的UTC时间
  • 执行者:执行启用/禁用操作的用户主体名称(UPN)
  • 目标用户:被操作的用户UPN
  • ActivityDisplayName:具体操作类型(启用/禁用账户)

二、使用AzureAD模块(兼容旧环境)

1. 前置准备

Install-Module AzureAD -Force -AllowClobber
Connect-AzureAD

2. 筛选目标日志

Get-AzureADAuditDirectoryLogs -Filter "createdDateTime ge 2023-05-29T00:00:00Z and createdDateTime le 2023-06-03T00:00:00Z" | 
Where-Object {$_.ActivityDisplayName -in "Disable user account", "Enable user account"} |
Select-Object CreatedDateTime,
              @{Name='执行者'; Expression={$_.InitiatedBy.User.UserPrincipalName}},
              @{Name='目标用户'; Expression={$_.TargetResources[0].UserPrincipalName}},
              ActivityDisplayName

补充说明

  • 若操作由应用程序触发(非人工操作),可查看InitiatedBy.App.DisplayName字段获取执行者信息
  • Azure AD审计日志默认保留90天,超出该范围的记录无法查询

内容的提问来源于stack exchange,提问作者Kegsy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 20:20:03