You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Microsoft Graph PowerShell将Azure资源访问管理切换为YES?

修正后的PowerShell脚本及问题说明

错误原因分析

  • cmdlet未识别:未安装或导入Microsoft Graph PowerShell模块,Get-MgDirectorySetting和Set-MgDirectorySetting属于该模块专属命令。
  • 属性名称错误:目标设置的正确属性为EnableAzureADRoleBasedAccessControl,而非脚本中写的EnableAadResourceAccessPolicy。

修正步骤及脚本

  1. 安装并导入Microsoft Graph PowerShell模块(首次运行需执行)
Install-Module Microsoft.Graph -Force -AllowClobber
Import-Module Microsoft.Graph.Identity.DirectoryManagement
  1. 连接到Microsoft Graph并获取所需权限
Connect-MgGraph -Scopes "Directory.ReadWrite.All"
  1. 获取目标目录设置并更新配置
# 获取"Access management for Azure resources"对应的目录设置对象
$directorySetting = Get-MgDirectorySetting -Filter "DisplayName eq 'Access management for Azure resources'"

# 定位到目标属性并设置为启用状态
$targetValue = $directorySetting.Values | Where-Object { $_.Name -eq "EnableAzureADRoleBasedAccessControl" }
$targetValue.Value = "True"

# 保存修改
Set-MgDirectorySetting -Id $directorySetting.Id -Values $directorySetting.Values

补充说明

若首次运行时找不到该目录设置对象,需先创建对应模板的实例:

$templateId = (Get-MgDirectorySettingTemplate | Where-Object { $_.DisplayName -eq 'Access management for Azure resources' }).Id
New-MgDirectorySetting -TemplateId $templateId -Values @(@{Name="EnableAzureADRoleBasedAccessControl"; Value="True"})

内容的提问来源于stack exchange,提问作者Venkatkaridi011

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 10:25:10