如何在Azure AD中实现立即取消用户配置,替代默认的30天软删除?
Absolutely, you can bypass Azure AD's default 30-day soft delete window and permanently remove a user immediately. The process involves two key steps: first soft-deleting the user (as Azure AD requires this initial step), then immediately purging them from the deleted items container. Here are the two most reliable methods to do this:
使用Microsoft Graph PowerShell
This is the most straightforward approach for admins who prefer PowerShell:
- First, connect to Microsoft Graph with the required permissions:
Connect-MgGraph -Scopes User.ReadWrite.All - If the user hasn’t been deleted yet, soft-delete them first:
Remove-MgUser -UserId "user@contoso.com" # Replace with the user's UPN or object ID - Next, permanently purge the soft-deleted user. You’ll need their object ID (you can retrieve it using
Get-MgDirectoryDeletedItem -Filter "userType eq 'Member'"to list all deleted users):Remove-MgDirectoryDeletedItem -DirectoryObjectId "USER_OBJECT_ID"
使用Microsoft Graph API
If you prefer working with REST APIs (or need to automate this in code):
- First, send a DELETE request to soft-delete the user (if not already deleted):
DELETE https://graph.microsoft.com/v1.0/users/{user-id} - Then, send a second DELETE request to permanently purge the user from the deleted items:
DELETE https://graph.microsoft.com/v1.0/directory/deletedItems/{user-id}
Note: You’ll need the
User.ReadWrite.AllorDirectory.ReadWrite.Allscope to perform these operations, and you must authenticate with an account that has admin privileges (Global Admin, User Admin, etc.).
Critical Notes
- Permanent deletion is irreversible: Once you purge the user, there’s no way to recover their account, data, or associated licenses. Double-check before executing the final purge.
- You can’t skip the soft-delete step: Azure AD requires all user deletions to first go through the soft-delete state before permanent removal is allowed.
内容的提问来源于stack exchange,提问作者Harish tej

