如何通过Bicep将VM的系统分配托管标识添加至现有AAD组?
将系统分配托管标识添加到现有AAD组(Bicep实现)
当然可以实现,你只需在现有Bicep部署中添加Microsoft.Groups/members资源,就能把VM系统分配标识的principalId加入目标AAD组。
实现代码示例
// 引用目标现有AAD组,替换为你的组对象ID resource targetAadGroup 'Microsoft.Groups@2022-07-01' existing = { name: 'your-target-group-object-id' } // 你的VM资源(保留原有配置) resource vm 'Microsoft.Compute/virtualMachines@2021-03-01' = { name: vmName location: location identity: { type: 'SystemAssigned' } // 其他VM配置项... } // 将VM的系统分配托管标识添加到AAD组 resource addVmIdentityToGroup 'Microsoft.Groups/members@2022-07-01' = { parent: targetAadGroup name: vm.identity.principalId properties: { '@odata.id': 'https://graph.microsoft.com/v1.0/directoryObjects/${vm.identity.principalId}' } }
关键注意事项
- 执行部署的账号必须拥有目标AAD组的成员管理权限(比如组管理员权限,或被授予添加成员的特定权限)
- 替换代码中的
your-target-group-object-id为实际AAD组的对象ID(可在Azure门户的AAD组详情页面获取) - 确保Groups资源的API版本兼容,示例中使用的
2022-07-01是稳定版本,可根据需要调整
内容的提问来源于stack exchange,提问作者Ask
相关产品推荐
相关产品推荐

