You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Azure Runbook中创建Sentinel自动化规则遇类型查找失败错误

问题解决:PowerShell Runbook中创建Sentinel自动化规则报错

问题描述

已导入SecurityInsights 5.1模块,本地VSCode PowerShell环境中能正常运行创建Sentinel自动化规则的脚本,但在Azure Automation Runbook中执行时报错,无法找到指定的.NET类型,且提示属性不存在。

原脚本:

$LogicAppResourceId = Get-AzLogicApp -ResourceGroupName "myResourceGroup" -Name "Reset-AADPassword"
 $automationRuleAction = [Microsoft.Azure.PowerShell.Cmdlets.SecurityInsights.Models.Api20210901Preview.AutomationRuleRunPlaybookAction]::new()
 $automationRuleAction.Order = 1
 $automationRuleAction.ActionType = "RunPlaybook"
 $automationRuleAction.ActionConfigurationLogicAppResourceId = ($LogicAppResourceId.Id)
 $automationRuleAction.ActionConfigurationTenantId = (Get-AzContext).Tenant.Id
 New-AzSentinelAutomationRule -ResourceGroupName "myResourceGroup" -WorkspaceName "myWorkspaceName" -Id ((New-Guid).Guid) -Action $automationRuleAction -DisplayName "Run Playbook to reset AAD password" -Order 2 -TriggeringLogicIsEnabled

翻译后的报错信息:

System.Management.Automation.RuntimeException: 无法找到类型 [Microsoft.Azure.PowerShell.Cmdlets.SecurityInsights.Models.Api20210901Preview.AutomationRuleRunPlaybookAction]。
   在 System.Management.Automation.TypeOps.ResolveTypeName(ITypeName typeName, IScriptExtent errorPos)
   在 System.Management.Automation.Interpreter.FuncCallInstruction`3.Run(InterpretedFrame frame)
   在 System.Management.Automation.Interpreter.EnterTryCatchFinallyInstruction.Run(InterpretedFrame frame)
System.Management.Automation.RuntimeException: 在此对象上找不到属性“Order”。请验证该属性是否存在并且可以设置。
   在 CallSite.Target(Closure , CallSite , Object , Int32 )
   在 System.Dynamic.UpdateDelegates.UpdateAndExecute2[T0,T1,TRet](CallSite site, T0 arg0, T1 arg1)
   在 System.Management.Automation.Interpreter.DynamicInstruction`3.Run(InterpretedFrame frame)
   在 System.Management.Automation.Interpreter.EnterTryCatchFinallyInstruction.Run(InterpretedFrame frame)
System.Management.Automation.RuntimeException: 在此对象上找不到属性“ActionType”。请验证该属性是否存在并且可以设置。
   在 CallSite.Target(Closure , CallSite , Object , String )
   在 System.Dynamic.UpdateDelegates.UpdateAndExecute2[T0,T1,TRet](CallSite site, T0 arg0, T1 arg1)
   在 System.Management.Automation.Interpreter.DynamicInstruction`3.Run(InterpretedFrame frame)
   在 System.Management.Automation.Interpreter.EnterTryCatchFinallyInstruction.Run(InterpretedFrame frame)
System.Management.Automation.RuntimeException: 在此对象上找不到属性“ActionConfigurationLogicAppResourceId”。

原因分析

Azure Automation Runbook的PowerShell运行环境与本地VSCode环境存在差异:直接实例化模块内部的.NET类型时,Runbook环境可能无法正确加载该类型的上下文,导致类型找不到,后续设置属性也会失败。

解决方案

改用SecurityInsights模块提供的专用cmdlet New-AzSentinelAutomationRuleRunPlaybookAction 来创建自动化规则动作对象,而不是手动实例化.NET类型。该cmdlet会确保对象在Runbook环境中正确初始化,所有属性都能被识别。

修改后的脚本:

# 获取逻辑应用资源
$logicApp = Get-AzLogicApp -ResourceGroupName "myResourceGroup" -Name "Reset-AADPassword"

# 使用模块cmdlet创建RunPlaybook动作对象
$automationRuleAction = New-AzSentinelAutomationRuleRunPlaybookAction `
    -Order 1 `
    -LogicAppResourceId $logicApp.Id `
    -TenantId (Get-AzContext).Tenant.Id

# 创建Sentinel自动化规则
New-AzSentinelAutomationRule `
    -ResourceGroupName "myResourceGroup" `
    -WorkspaceName "myWorkspaceName" `
    -Id (New-Guid).Guid `
    -Action $automationRuleAction `
    -DisplayName "Run Playbook to reset AAD password" `
    -Order 2 `
    -TriggeringLogicIsEnabled

额外检查点

  1. 确认Azure Automation账户中已正确导入SecurityInsights 5.1模块:进入Automation账户的「模块」页面,检查模块状态为「已导入」,若只是上传未导入,需手动触发导入。
  2. 确保Runbook使用的托管身份(或运行账户)拥有访问目标Logic App和Sentinel工作区的权限,避免后续执行时出现权限问题。

内容的提问来源于stack exchange,提问作者dev333

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 04:55:13