如何通过PowerShell为Microsoft 365动态组添加所有者?
问题
尝试通过PowerShell为Microsoft 365动态统一组添加所有者时失败,但在GUI中可正常完成操作:
- 先尝试添加用户为成员时,报错:
PS C:\WINDOWS\system32> Add-UnifiedGroupLinks -Identity "Klas_1A1F_22-23" -LinkType "Members" -Links "a****es.desa*****r@***.be" Membership for this group is managed automatically by using a rule. Edit the membership rule to change the group membership. + CategoryInfo : NotSpecified: (Klas_1A1F_22-23...5a-2170b2539977:ADObjectId) [Add-UnifiedGroupLinks], DynamicGroupMem...DeniedException + FullyQualifiedErrorId : [Server=PA4PR03MB6992,RequestId=cec5e218-c170-4d2d-8108-d529910bc7b5,TimeStamp=13/12/2022 20:28:38] [FailureCategory=Cmdlet-DynamicGroupMembershipChangeDeniedException] D3C4100,Microsoft.Exchange.Management.RecipientTasks.AddUnifiedGroupLinks + PSComputerName : outlook.office365.com
- 直接添加用户为所有者时,报错:
PS C:\WINDOWS\system32> Add-UnifiedGroupLinks -Identity "Klas_1A1F_22-23" -LinkType "Owners" -Links "a****es.desa*****r@***.be" Only Members can be Owners of a group. Please add 'annelies.desaeger' first as members before adding them as owners. + CategoryInfo : NotSpecified: (Klas_1A1F_22-23...5a-2170b2539977:ADObjectId) [Add-UnifiedGroupLinks], ADNotAMemberException + FullyQualifiedErrorId : [Server=PA4PR03MB6992,RequestId=1ee4f0e9-aa80-4903-9702-c9bca9ef625d,TimeStamp=13/12/2022 20:28:59] [FailureCategory=Cmdlet-ADNotAMemberException] 9B67D48,Microsoft.Exchange.Management.RecipientTasks.AddUnifiedGroupLinks + PSComputerName : outlook.office365.com
解决方案
方案1:使用Exchange PowerShell的Set-UnifiedGroup命令
Add-UnifiedGroupLinks要求所有者必须是组内成员,但动态组无法手动添加成员,因此改用Set-UnifiedGroup直接修改组的所有者属性:
- 获取当前组的所有者列表(避免覆盖现有所有者):
$currentOwners = (Get-UnifiedGroup -Identity "Klas_1A1F_22-23").Owners
- 将新用户添加到所有者列表:
$newOwner = (Get-Mailbox "annelies.desaeger@xxx.be").Identity $currentOwners += $newOwner
- 更新组的所有者:
Set-UnifiedGroup -Identity "Klas_1A1F_22-23" -Owners $currentOwners
如果需要一次性设置多个所有者(覆盖原有列表),可直接指定:
Set-UnifiedGroup -Identity "Klas_1A1F_22-23" -Owners @("annelies.desaeger@xxx.be", "existing-owner@xxx.be")
方案2:使用Azure AD PowerShell模块
- 连接到Azure AD:
Connect-AzureAD
- 获取目标组和用户的对象ID:
$group = Get-AzureADGroup -Filter "DisplayName eq 'Klas_1A1F_22-23'" $user = Get-AzureADUser -Filter "UserPrincipalName eq 'annelies.desaeger@xxx.be'"
- 添加所有者:
Add-AzureADGroupOwner -ObjectId $group.ObjectId -RefObjectId $user.ObjectId
方案3:使用Microsoft Graph PowerShell模块
- 连接到Microsoft Graph(需要
Group.ReadWrite.All权限):
Connect-MgGraph -Scopes Group.ReadWrite.All
- 获取目标组和用户的ID:
$group = Get-MgGroup -Filter "DisplayName eq 'Klas_1A1F_22-23'" $user = Get-MgUser -Filter "UserPrincipalName eq 'annelies.desaeger@xxx.be'"
- 添加所有者:
New-MgGroupOwnerByRef -GroupId $group.Id -DirectoryObjectId $user.Id
原因说明
Add-UnifiedGroupLinks的设计逻辑要求统一组的所有者必须同时是组成员,但动态统一组的成员资格由规则自动管理,无法手动添加,因此该命令不适用于动态组的所有者添加操作。而上述方案中的命令直接操作组的所有者属性,无需依赖成员身份,与GUI的操作逻辑一致,因此可以成功完成添加。
内容的提问来源于stack exchange,提问作者MisterS
相关产品推荐
相关产品推荐

