You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell或CLI筛选自定义Azure目录角色?

解决方法

一、通过PowerShell获取自定义目录角色

方法1:使用Microsoft Graph PowerShell模块

# 安装模块(首次使用)
Install-Module Microsoft.Graph -Scope CurrentUser
# 连接并获取目录角色读取权限
Connect-MgGraph -Scopes "RoleManagement.Read.Directory"
# 筛选出所有自定义目录角色
Get-MgDirectoryRoleDefinition | Where-Object { $_.IsBuiltIn -eq $false }

方法2:使用AzureAD模块(旧版兼容方案)

# 安装模块
Install-Module AzureAD -Scope CurrentUser
# 连接Azure AD
Connect-AzureAD
# 筛选自定义目录角色
Get-AzureADDirectoryRoleTemplate | Where-Object { $_.IsBuiltIn -eq $false }

二、通过Azure CLI获取自定义目录角色

# 登录Azure CLI
az login
# 过滤并返回自定义目录角色
az ad role definition list --filter "isBuiltIn eq false"

三、筛选Get-AzRoleDefinition返回的自定义角色

Get-AzRoleDefinition针对的是Azure资源RBAC角色(区别于Azure AD目录角色),自定义RBAC角色的IsCustom属性为true,可通过以下方式筛选:

方式1:用Where-Object过滤

Get-AzRoleDefinition | Where-Object { $_.IsCustom -eq $true }

方式2:使用内置参数(部分PowerShell版本支持)

Get-AzRoleDefinition -Custom

内容的提问来源于stack exchange,提问作者Sanam7

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 04:06:13