Intune Graph API:如何按组ID过滤已分配的macOS VPP应用
修正后的Graph API查询语句
要按特定组过滤被设为「required」的macOS VPP应用,需要针对target的派生类型进行类型转换后再访问groupId——因为deviceAndAppManagementAssignmentTarget是抽象基类,groupId仅属于它的派生类型groupAssignmentTarget。
正确的查询语句如下:
https://graph.microsoft.com/beta/deviceAppManagement/mobileApps?$filter=isof('microsoft.graph.macOsVppApp') and isAssigned eq true&$expand=assignments($select=intent,target;$filter=intent eq 'required' and isof(target, 'microsoft.graph.groupAssignmentTarget') and cast(target, 'microsoft.graph.groupAssignmentTarget').groupId eq '14etcblahblah')
关键修正点说明
- 添加
isof(target, 'microsoft.graph.groupAssignmentTarget'):先判断分配目标是否为组类型,避免对其他类型目标(如全设备、单个用户)进行无效属性访问 - 使用
cast(target, 'microsoft.graph.groupAssignmentTarget').groupId:将抽象的target转换为具体的groupAssignmentTarget类型,之后才能合法访问groupId属性 - 保留原有的
intent eq 'required'条件,确保只筛选「必需」分配的应用
执行该查询后,会返回同时满足以下条件的macOS VPP应用:
- 已被分配(
isAssigned eq true) - 存在针对指定组的「required」类型分配记录
内容的提问来源于stack exchange,提问作者jimmyl2023
相关产品推荐
相关产品推荐

