如何锁定Azure中的Invoke-AzVMRunCommand PowerShell cmdlet?
精准禁用Azure中Invoke-AzVMRunCommand cmdlet的方法
关键权限定位
Invoke-AzVMRunCommand对应的核心RBAC权限是 Microsoft.Compute/virtualMachines/runCommand/action,该权限直接控制VM上远程执行命令的操作,和你之前看到的Azure Automation权限无关(Automation权限仅针对自动化账户作业,不影响VM层面的runCommand)。
精准禁用步骤
- 针对自定义IAM角色,添加**拒绝(Deny)**规则,指定权限为
Microsoft.Compute/virtualMachines/runCommand/action - 拒绝权限优先级高于允许权限,即使用户拥有其他包含该权限的角色,此拒绝规则也会生效,无需批量移除其他Compute相关权限
- 可以将该拒绝规则应用到特定用户、组或范围(如订阅、资源组、单个VM),实现细粒度控制
验证配置
配置完成后,让目标用户执行Invoke-AzVMRunCommand,若返回以下类似错误,则说明权限设置生效:
The client '<用户ID>' with object id '<对象ID>' does not have authorization to perform action 'Microsoft.Compute/virtualMachines/runCommand/action' over scope '/subscriptions/<订阅ID>/resourceGroups/<资源组名>/providers/Microsoft.Compute/virtualMachines/<VM名>' or the scope is invalid. If access was recently granted, please refresh your credentials.
内容的提问来源于stack exchange,提问作者Superfluxus
相关产品推荐
相关产品推荐

