如何通过Bicep获取Azure AD域名?
通过Bicep获取Azure AD域名的方法
Bicep的内置函数(如environment()、subscription())确实不直接提供Azure AD域名的获取能力,不过可以通过以下两种方式实现:
手动传入参数
这是最简单直接的方式,在部署时将Azure AD域名作为参数传入模板,后续在需要的地方引用即可:param aadDomainName string = 'example.com' // 示例:在存储账户资源中使用该参数 resource exampleStorage 'Microsoft.Storage/storageAccounts@2023-01-01' = { name: 'stor${uniqueString(aadDomainName)}' location: resourceGroup().location sku: { name: 'Standard_LRS' } kind: 'StorageV2' }通过部署脚本动态获取
可以在Bicep中使用deploymentScript资源,调用Azure PowerShell查询租户的默认验证域名,并将结果输出供模板使用:resource getAadDefaultDomain 'Microsoft.Resources/deploymentScripts@2020-10-01' = { name: 'getAadDefaultDomain' location: resourceGroup().location kind: 'AzurePowerShell' properties: { azPowerShellVersion: '7.2' scriptContent: ''' # 获取租户默认验证域名 $defaultDomain = Get-AzTenantDetail | Select-Object -ExpandProperty VerifiedDomains | Where-Object { $_.IsDefault -eq $true } | Select-Object -ExpandProperty Name Write-Output $defaultDomain ''' retentionInterval: 'PT1H' outputCommand: '$defaultDomain' } } // 输出获取到的域名,也可在模板其他资源中直接引用 output aadDefaultDomainName string = getAadDefaultDomain.properties.outputs[0]注意:使用这种方式需要确保部署脚本的托管标识拥有读取租户信息的权限(如
Directory.Read.All)。
内容的提问来源于stack exchange,提问作者Adam
相关产品推荐
相关产品推荐

