在Azure Runbook中创建Sentinel自动化规则遇类型查找失败错误
问题解决:PowerShell Runbook中创建Sentinel自动化规则报错
问题描述
已导入SecurityInsights 5.1模块,本地VSCode PowerShell环境中能正常运行创建Sentinel自动化规则的脚本,但在Azure Automation Runbook中执行时报错,无法找到指定的.NET类型,且提示属性不存在。
原脚本:
$LogicAppResourceId = Get-AzLogicApp -ResourceGroupName "myResourceGroup" -Name "Reset-AADPassword" $automationRuleAction = [Microsoft.Azure.PowerShell.Cmdlets.SecurityInsights.Models.Api20210901Preview.AutomationRuleRunPlaybookAction]::new() $automationRuleAction.Order = 1 $automationRuleAction.ActionType = "RunPlaybook" $automationRuleAction.ActionConfigurationLogicAppResourceId = ($LogicAppResourceId.Id) $automationRuleAction.ActionConfigurationTenantId = (Get-AzContext).Tenant.Id New-AzSentinelAutomationRule -ResourceGroupName "myResourceGroup" -WorkspaceName "myWorkspaceName" -Id ((New-Guid).Guid) -Action $automationRuleAction -DisplayName "Run Playbook to reset AAD password" -Order 2 -TriggeringLogicIsEnabled
翻译后的报错信息:
System.Management.Automation.RuntimeException: 无法找到类型 [Microsoft.Azure.PowerShell.Cmdlets.SecurityInsights.Models.Api20210901Preview.AutomationRuleRunPlaybookAction]。 在 System.Management.Automation.TypeOps.ResolveTypeName(ITypeName typeName, IScriptExtent errorPos) 在 System.Management.Automation.Interpreter.FuncCallInstruction`3.Run(InterpretedFrame frame) 在 System.Management.Automation.Interpreter.EnterTryCatchFinallyInstruction.Run(InterpretedFrame frame) System.Management.Automation.RuntimeException: 在此对象上找不到属性“Order”。请验证该属性是否存在并且可以设置。 在 CallSite.Target(Closure , CallSite , Object , Int32 ) 在 System.Dynamic.UpdateDelegates.UpdateAndExecute2[T0,T1,TRet](CallSite site, T0 arg0, T1 arg1) 在 System.Management.Automation.Interpreter.DynamicInstruction`3.Run(InterpretedFrame frame) 在 System.Management.Automation.Interpreter.EnterTryCatchFinallyInstruction.Run(InterpretedFrame frame) System.Management.Automation.RuntimeException: 在此对象上找不到属性“ActionType”。请验证该属性是否存在并且可以设置。 在 CallSite.Target(Closure , CallSite , Object , String ) 在 System.Dynamic.UpdateDelegates.UpdateAndExecute2[T0,T1,TRet](CallSite site, T0 arg0, T1 arg1) 在 System.Management.Automation.Interpreter.DynamicInstruction`3.Run(InterpretedFrame frame) 在 System.Management.Automation.Interpreter.EnterTryCatchFinallyInstruction.Run(InterpretedFrame frame) System.Management.Automation.RuntimeException: 在此对象上找不到属性“ActionConfigurationLogicAppResourceId”。
原因分析
Azure Automation Runbook的PowerShell运行环境与本地VSCode环境存在差异:直接实例化模块内部的.NET类型时,Runbook环境可能无法正确加载该类型的上下文,导致类型找不到,后续设置属性也会失败。
解决方案
改用SecurityInsights模块提供的专用cmdlet New-AzSentinelAutomationRuleRunPlaybookAction 来创建自动化规则动作对象,而不是手动实例化.NET类型。该cmdlet会确保对象在Runbook环境中正确初始化,所有属性都能被识别。
修改后的脚本:
# 获取逻辑应用资源 $logicApp = Get-AzLogicApp -ResourceGroupName "myResourceGroup" -Name "Reset-AADPassword" # 使用模块cmdlet创建RunPlaybook动作对象 $automationRuleAction = New-AzSentinelAutomationRuleRunPlaybookAction ` -Order 1 ` -LogicAppResourceId $logicApp.Id ` -TenantId (Get-AzContext).Tenant.Id # 创建Sentinel自动化规则 New-AzSentinelAutomationRule ` -ResourceGroupName "myResourceGroup" ` -WorkspaceName "myWorkspaceName" ` -Id (New-Guid).Guid ` -Action $automationRuleAction ` -DisplayName "Run Playbook to reset AAD password" ` -Order 2 ` -TriggeringLogicIsEnabled
额外检查点
- 确认Azure Automation账户中已正确导入SecurityInsights 5.1模块:进入Automation账户的「模块」页面,检查模块状态为「已导入」,若只是上传未导入,需手动触发导入。
- 确保Runbook使用的托管身份(或运行账户)拥有访问目标Logic App和Sentinel工作区的权限,避免后续执行时出现权限问题。
内容的提问来源于stack exchange,提问作者dev333
相关产品推荐
相关产品推荐

