PowerShell执行Azure DevOps CLI权限更新遇类型转换错误求助
解决Azure DevOps CLI权限更新错误及后续Azure AD组创建步骤
权限更新错误原因与解决方法
错误根源
执行az devops security permission update时出现Could not cast or convert from System.String to Microsoft.VisualStudio.Services.Identity.IdentityDescriptor,是因为你直接将Azure AD组名、用户名这类普通字符串传给了--subject参数,但该参数要求传入Identity Descriptor(Azure DevOps用来唯一标识身份的格式字符串),而非原始名称。
解决步骤
获取目标身份的Identity Descriptor
- 如果是Azure AD组,先通过Azure CLI获取组的Object ID,再查询对应descriptor:
# 获取Azure AD组的Object ID $groupId = az ad group show --group "你的AD组名称" --query id -o tsv # 查询该组在Azure DevOps中的Identity Descriptor $descriptor = az devops security identity list --search-query $groupId --query "[0].descriptor" -o tsv - 如果是Azure DevOps本地组/用户,直接用名称查询:
$descriptor = az devops security identity list --search-query "目标身份名称" --query "[0].descriptor" -o tsv
- 如果是Azure AD组,先通过Azure CLI获取组的Object ID,再查询对应descriptor:
使用Descriptor执行权限更新
将拿到的$descriptor传入--subject参数,示例命令:az devops security permission update ` --id "repoV2" ` --subject $descriptor ` --allow-bitmask 1 ` # 1代表读取权限,可根据需求调整位掩码 --resource "repo/你的仓库ID" ` --org "https://dev.azure.com/你的组织名" ` --project "你的项目名"
用PowerShell创建Azure AD组
使用Az模块完成创建,步骤如下:
- 安装并导入Az.Resources模块
Install-Module -Name Az.Resources -Force -AllowClobber Import-Module Az.Resources - 登录Azure账户
Connect-AzAccount - 创建Azure AD组
创建完成后,即可用前面的方法获取该组的descriptor,再配置到Azure DevOps仓库权限中。New-AzADGroup ` -DisplayName "你的AD组显示名称" ` -MailNickname "AD组邮件别名" ` -Description "组描述"
内容的提问来源于stack exchange,提问作者objectclass
相关产品推荐
相关产品推荐

