You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何基于用户组创建Azure/Intune/MS Endpoint Manager设备组?

基于用户组成员在Azure/Intune创建设备组的临时解决方案

由于动态组查询引擎无法直接关联用户组与设备,以下是几种可落地的临时方案:

方案1:PowerShell脚本定期同步

通过Microsoft Graph API编写脚本,手动或定时执行用户组到设备组的同步:

  1. 连接到Microsoft Graph API(需DeviceManagementManagedDevices.ReadWrite.All、GroupMember.Read.All、Group.ReadWrite.All权限)
  2. 获取目标用户组的所有成员ID
  3. 遍历每个用户,查询其关联的Intune注册设备
  4. 将这些设备批量添加到目标设备组中

示例脚本片段:

# 连接Graph API
Connect-MgGraph -Scopes "DeviceManagementManagedDevices.ReadWrite.All","GroupMember.Read.All","Group.ReadWrite.All"

# 定义用户组ID和目标设备组ID
$userGroupId = "你的用户组ID"
$deviceGroupId = "你的目标设备组ID"

# 获取用户组成员
$users = Get-MgGroupMember -GroupId $userGroupId -All

# 收集所有关联设备ID
$deviceIds = @()
foreach ($user in $users) {
    $devices = Get-MgUserOwnedDevice -UserId $user.Id -Filter "deviceType eq 'Windows'" # 可按需筛选设备类型
    $deviceIds += $devices.Id
}

# 移除设备组中现有非目标设备(可选)
$currentDevices = Get-MgGroupMember -GroupId $deviceGroupId -All
foreach ($device in $currentDevices) {
    if ($device.Id -notin $deviceIds) {
        Remove-MgGroupMemberByRef -GroupId $deviceGroupId -DirectoryObjectId $device.Id
    }
}

# 添加新设备到组
foreach ($deviceId in $deviceIds) {
    if ($deviceId -notin $currentDevices.Id) {
        New-MgGroupMemberByRef -GroupId $deviceGroupId -DirectoryObjectId $deviceId
    }
}
  • 优点:灵活可控,可自定义筛选条件(如设备类型)
  • 缺点:需手动或通过任务计划定期执行,无实时同步

方案2:逻辑应用(Logic Apps)实现自动化同步

利用Azure逻辑应用配置触发机制,实现用户组变化时自动同步设备:

  1. 创建逻辑应用,设置触发器(如“当Azure AD组成员变化时”或定时触发器)
  2. 添加“调用Microsoft Graph API”动作,获取用户组成员
  3. 遍历成员,查询其关联设备
  4. 批量添加/移除设备到目标设备组
  • 优点:自动化程度高,可配置实时或定时同步
  • 缺点:需熟悉逻辑应用配置,依赖Azure资源

方案3:手动关联(小团队场景)

如果用户组规模较小,可手动导出用户组成员,在Intune中搜索每个用户的设备,手动添加到设备组。

  • 优点:无需技术配置,快速上手
  • 缺点:仅适用于小范围场景,维护成本高

内容的提问来源于stack exchange,提问作者GB-CCSA

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 16:50:23