You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell执行Azure DevOps CLI权限更新遇类型转换错误求助

解决Azure DevOps CLI权限更新错误及后续Azure AD组创建步骤

权限更新错误原因与解决方法

错误根源

执行az devops security permission update时出现Could not cast or convert from System.String to Microsoft.VisualStudio.Services.Identity.IdentityDescriptor,是因为你直接将Azure AD组名、用户名这类普通字符串传给了--subject参数,但该参数要求传入Identity Descriptor(Azure DevOps用来唯一标识身份的格式字符串),而非原始名称。

解决步骤

  1. 获取目标身份的Identity Descriptor

    • 如果是Azure AD组,先通过Azure CLI获取组的Object ID,再查询对应descriptor:
      # 获取Azure AD组的Object ID
      $groupId = az ad group show --group "你的AD组名称" --query id -o tsv
      
      # 查询该组在Azure DevOps中的Identity Descriptor
      $descriptor = az devops security identity list --search-query $groupId --query "[0].descriptor" -o tsv
      
    • 如果是Azure DevOps本地组/用户,直接用名称查询:
      $descriptor = az devops security identity list --search-query "目标身份名称" --query "[0].descriptor" -o tsv
      
  2. 使用Descriptor执行权限更新
    将拿到的$descriptor传入--subject参数,示例命令:

    az devops security permission update `
      --id "repoV2" `
      --subject $descriptor `
      --allow-bitmask 1 ` # 1代表读取权限,可根据需求调整位掩码
      --resource "repo/你的仓库ID" `
      --org "https://dev.azure.com/你的组织名" `
      --project "你的项目名"
    

用PowerShell创建Azure AD组

使用Az模块完成创建,步骤如下:

  1. 安装并导入Az.Resources模块
    Install-Module -Name Az.Resources -Force -AllowClobber
    Import-Module Az.Resources
    
  2. 登录Azure账户
    Connect-AzAccount
    
  3. 创建Azure AD组
    New-AzADGroup `
      -DisplayName "你的AD组显示名称" `
      -MailNickname "AD组邮件别名" `
      -Description "组描述"
    
    创建完成后,即可用前面的方法获取该组的descriptor,再配置到Azure DevOps仓库权限中。

内容的提问来源于stack exchange,提问作者objectclass

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 08:05:22