You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell设置Azure App Service的SCM访问限制为拒绝?

解决Azure SCM IP安全限制拒绝设置失效问题

问题原因

你当前代码的问题在于scmIpSecurityRestrictions是数组类型,而非单个哈希表对象,而且缺少IP安全限制所需的必填字段(比如规则名称、IP地址、优先级等),导致设置不生效。

正确的PowerShell代码

要正确设置SCM的拒绝规则,需要将scmIpSecurityRestrictions定义为数组,并且包含完整的规则参数:

$propertiesObject = @{
    http20Enabled = $true;
    ScmIpSecurityRestrictionsUseMain = $true;
    scmIpSecurityRestrictions = @(
        @{
            Action = "Deny"
            Name = "DenyAllSCM" # 自定义规则名称
            IPAddress = "0.0.0.0/0" # 拒绝所有IP
            Priority = 100 # 优先级,数值越小规则越先执行
            Description = "拒绝所有访问SCM站点的请求"
        }
    )
}

Set-AzResource -PropertyObject $propertiesObject -ResourceGroupName $AppServiceRG -ResourceType Microsoft.Web/sites/config -ResourceName "$AppServiceName/web" -ApiVersion 2022-03-01 -Force

关键说明

  • scmIpSecurityRestrictions必须是数组(用@()包裹),即便只有一条规则
  • 每条规则必须包含Action、Name、IPAddress、Priority这几个必填字段
  • 如果需要允许特定IP再拒绝其他,可以添加多条规则,注意优先级设置(比如先允许特定IP,优先级设为50,再拒绝所有,优先级100)

内容的提问来源于stack exchange,提问作者Emanuele

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 13:15:32