You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Graph API向Intune脚本分配组和设备时遇400错误求助

排查Intune Graph API脚本分配400错误的步骤

1. 替换URL中的占位符

URL中的%7Bid%7D是{id}的URL编码,必须替换为实际的设备管理脚本ID,不能保留占位符。

2. 移除请求体中手动指定的ID字段

deviceManagementScriptGroupAssignments和deviceManagementScriptAssignments里的id字段由系统自动生成,提交请求时无需手动设置,直接移除这两个字段即可。

3. 修正请求体结构

官方beta版API要求将所有分配项放在assignments数组中,而非分开的两个数组。修正后的请求体示例:

{
  "assignments": [
    {
      "@odata.type": "#microsoft.graph.deviceManagementScriptGroupAssignment",
      "targetGroupId": "你的实际组ID"
    },
    {
      "@odata.type": "#microsoft.graph.deviceManagementScriptAssignment",
      "target": {
        "@odata.type": "#microsoft.graph.allDevicesAssignmentTarget",
        "deviceAndAppManagementAssignmentFilterId": null,
        "deviceAndAppManagementAssignmentFilterType": "none"
      }
    }
  ]
}

4. 验证权限配置

确保调用API的账号已被授予DeviceManagementConfiguration.ReadWrite.All权限,且完成了管理员同意授权。

5. 检查目标对象有效性

  • 确认targetGroupId对应的是Intune中的设备组,而非用户组;
  • 若使用设备分配目标,确认allDevicesAssignmentTarget的配置无冲突(过滤器ID设为null、类型设为none是合理的,但需确保没有其他隐性配置错误)。

6. 确认API版本一致性

确保使用的beta版端点与请求体结构匹配,避免混用v1.0和beta版本的字段要求。

内容的提问来源于stack exchange,提问作者Yossi Nisani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 05:05:14