You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何获取Azure租户内所有资源类型(含存储账户子资源)?

解决Azure Resource Graph无法获取存储账户子资源的问题

问题原因

Azure Resource Graph仅索引控制平面级别的资源(如存储账户实例),而Blob容器、队列、表、文件共享属于存储账户的数据平面子资源,不在Resource Graph的默认检索范围内,因此无法直接通过Resource Graph查询到这些子资源。

方案1:使用Azure PowerShell直接查询存储子资源

通过遍历租户内所有存储账户,直接访问数据平面获取子资源,整理成你需要的格式:

# 获取租户内所有存储账户
$storageAccounts = Get-AzStorageAccount

# 初始化结果数组
$resourceList = @()

# 遍历存储账户,收集自身及子资源信息
foreach ($sa in $storageAccounts) {
    $context = $sa.Context

    # 添加存储账户本身
    $resourceList += [PSCustomObject]@{
        type   = $sa.Type
        kind   = $sa.Kind
        any_id = $sa.Id
    }

    # 查询Blob容器
    $blobContainers = Get-AzStorageContainer -Context $context
    foreach ($container in $blobContainers) {
        $resourceList += [PSCustomObject]@{
            type   = "Microsoft.Storage/storageAccounts/blobServices/containers"
            kind   = "BlobContainer"
            any_id = "$($sa.Id)/blobServices/default/containers/$($container.Name)"
        }
    }

    # 查询队列
    $queues = Get-AzStorageQueue -Context $context
    foreach ($queue in $queues) {
        $resourceList += [PSCustomObject]@{
            type   = "Microsoft.Storage/storageAccounts/queueServices/queues"
            kind   = "Queue"
            any_id = "$($sa.Id)/queueServices/default/queues/$($queue.Name)"
        }
    }

    # 查询表
    $tables = Get-AzStorageTable -Context $context
    foreach ($table in $tables) {
        $resourceList += [PSCustomObject]@{
            type   = "Microsoft.Storage/storageAccounts/tableServices/tables"
            kind   = "Table"
            any_id = "$($sa.Id)/tableServices/default/tables/$($table.Name)"
        }
    }

    # 查询文件共享
    $fileShares = Get-AzStorageShare -Context $context
    foreach ($share in $fileShares) {
        $resourceList += [PSCustomObject]@{
            type   = "Microsoft.Storage/storageAccounts/fileServices/shares"
            kind   = "FileShare"
            any_id = "$($sa.Id)/fileServices/default/shares/$($share.Name)"
        }
    }
}

# 去重并按类型排序(匹配原有处理逻辑)
$uniqueResources = $resourceList | Group-Object type | ForEach-Object { $_.Group[0] } | Sort-Object -Property type

$uniqueResources

方案2:混合使用Resource Graph与数据平面查询

先用Resource Graph高效获取所有存储账户列表,再批量查询子资源,适合租户内存储账户较多的场景:

# 用Resource Graph获取所有存储账户
$query = 'Resources | where type == "Microsoft.Storage/storageAccounts" | project id, type, kind'
$restSplat = @{
    Uri         = 'https://management.azure.com/providers/Microsoft.ResourceGraph/resources?api-version=2020-04-01-preview'
    Method      = 'Post'
    Body        = @{
        query             = $query
        managementGroupId = $ManagementGroupId
    } | ConvertTo-Json
    ContentType = 'application/json'
    headers     = @{"Authorization" = "Bearer $($AzToken.Token)"}
}
$storageAccountsFromGraph = Invoke-RestMethod @restSplat

# 初始化结果数组,先添加存储账户信息
$resourceList = $storageAccountsFromGraph.data.rows | ForEach-Object {
    [PSCustomObject]@{
        type   = $_[1]
        kind   = $_[2]
        any_id = $_[0]
    }
}

# 遍历存储账户ID,查询子资源
foreach ($saRow in $storageAccountsFromGraph.data.rows) {
    $saId = $saRow[0]
    # 从资源ID拆分出订阅、资源组、存储账户名
    $saParts = $saId -split '/', 8
    $subscriptionId = $saParts[2]
    $resourceGroupName = $saParts[4]
    $storageAccountName = $saParts[8]

    # 获取存储账户上下文
    $context = New-AzStorageContext -StorageAccountName $storageAccountName -UseConnectedAccount

    # 以下查询逻辑同方案1,依次添加Blob容器、队列、表、文件共享
    $blobContainers = Get-AzStorageContainer -Context $context
    foreach ($container in $blobContainers) {
        $resourceList += [PSCustomObject]@{
            type   = "Microsoft.Storage/storageAccounts/blobServices/containers"
            kind   = "BlobContainer"
            any_id = "$saId/blobServices/default/containers/$($container.Name)"
        }
    }

    # 队列、表、文件共享的查询代码省略,参考方案1即可
}

# 去重并排序
$uniqueResources = $resourceList | Group-Object type | ForEach-Object { $_.Group[0] } | Sort-Object -Property type

$uniqueResources

注意事项

  • 数据平面查询需要对应权限:如Storage Blob Data Contributor、Storage Queue Data Contributor等,确保当前账号拥有足够权限访问目标存储子资源。
  • 若租户内存储账户数量庞大,建议添加分页或批量处理逻辑,避免请求超时。

内容的提问来源于stack exchange,提问作者Nadia Hansen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 12:35:31