如何基于用户组创建Azure/Intune/MS Endpoint Manager设备组?
基于用户组成员在Azure/Intune创建设备组的临时解决方案
由于动态组查询引擎无法直接关联用户组与设备,以下是几种可落地的临时方案:
方案1:PowerShell脚本定期同步
通过Microsoft Graph API编写脚本,手动或定时执行用户组到设备组的同步:
- 连接到Microsoft Graph API(需
DeviceManagementManagedDevices.ReadWrite.All、GroupMember.Read.All、Group.ReadWrite.All权限) - 获取目标用户组的所有成员ID
- 遍历每个用户,查询其关联的Intune注册设备
- 将这些设备批量添加到目标设备组中
示例脚本片段:
# 连接Graph API Connect-MgGraph -Scopes "DeviceManagementManagedDevices.ReadWrite.All","GroupMember.Read.All","Group.ReadWrite.All" # 定义用户组ID和目标设备组ID $userGroupId = "你的用户组ID" $deviceGroupId = "你的目标设备组ID" # 获取用户组成员 $users = Get-MgGroupMember -GroupId $userGroupId -All # 收集所有关联设备ID $deviceIds = @() foreach ($user in $users) { $devices = Get-MgUserOwnedDevice -UserId $user.Id -Filter "deviceType eq 'Windows'" # 可按需筛选设备类型 $deviceIds += $devices.Id } # 移除设备组中现有非目标设备(可选) $currentDevices = Get-MgGroupMember -GroupId $deviceGroupId -All foreach ($device in $currentDevices) { if ($device.Id -notin $deviceIds) { Remove-MgGroupMemberByRef -GroupId $deviceGroupId -DirectoryObjectId $device.Id } } # 添加新设备到组 foreach ($deviceId in $deviceIds) { if ($deviceId -notin $currentDevices.Id) { New-MgGroupMemberByRef -GroupId $deviceGroupId -DirectoryObjectId $deviceId } }
- 优点:灵活可控,可自定义筛选条件(如设备类型)
- 缺点:需手动或通过任务计划定期执行,无实时同步
方案2:逻辑应用(Logic Apps)实现自动化同步
利用Azure逻辑应用配置触发机制,实现用户组变化时自动同步设备:
- 创建逻辑应用,设置触发器(如“当Azure AD组成员变化时”或定时触发器)
- 添加“调用Microsoft Graph API”动作,获取用户组成员
- 遍历成员,查询其关联设备
- 批量添加/移除设备到目标设备组
- 优点:自动化程度高,可配置实时或定时同步
- 缺点:需熟悉逻辑应用配置,依赖Azure资源
方案3:手动关联(小团队场景)
如果用户组规模较小,可手动导出用户组成员,在Intune中搜索每个用户的设备,手动添加到设备组。
- 优点:无需技术配置,快速上手
- 缺点:仅适用于小范围场景,维护成本高
内容的提问来源于stack exchange,提问作者GB-CCSA
相关产品推荐
相关产品推荐

