通过PowerShell调用MS Graph API获取Azure AD组及成员完整信息
解决Azure AD组及关联多类型成员导出问题
核心优化思路
1. 直接获取成员的displayName(无需额外调用cmdlet)
Get-MgGroupMember默认返回字段有限,但可以通过-Property参数指定需要的属性,直接拉取displayName和oDataType(对象类型标识),避免反复调用其他Get命令:
Get-MgGroupMember -GroupId $group.Id -All -Property "displayName,id,oDataType"
一次请求就能拿到成员的显示名称和类型,效率大幅提升。
2. 根据对象类型获取详细属性
如果需要不同类型对象的专属属性(比如用户的UPN、联系人的邮件),可以通过oDataType判断对象类型,再分支调用对应cmdlet。oDataType的格式是#microsoft.graph.user/#microsoft.graph.group/#microsoft.graph.contact,提取后缀即可判断类型。
优化后的脚本(支持所有成员类型,输出CSV更规范)
脚本1:仅导出组+成员ID+显示名称+类型
# 连接Graph,需提前赋予Group.Read.All权限 Connect-MgGraph -Scopes "Group.Read.All" # 初始化结果数组 $results = @() # 获取所有组 $groups = Get-MgGroup -All -Property "displayName,id" foreach ($group in $groups) { # 获取组内所有成员,指定需要的属性 $members = Get-MgGroupMember -GroupId $group.Id -All -Property "displayName,id,oDataType" foreach ($member in $members) { # 提取对象类型(去掉#microsoft.graph.前缀) $memberType = $member.ODataType -replace "#microsoft.graph.", "" # 组装结果对象 $resultObj = [PSCustomObject]@{ GroupName = $group.DisplayName GroupId = $group.Id MemberId = $member.Id MemberName = $member.DisplayName MemberType = $memberType } $results += $resultObj } } # 导出到CSV文件(比TXT更易处理) $results | Export-Csv -Path "C:\scripts\Azure_Groups_Members.csv" -NoTypeInformation -Encoding UTF8
脚本2:导出不同类型成员的详细属性
如果需要用户的UPN、邮件,联系人的邮件等信息,用这个版本:
# 连接Graph,需赋予对应权限:Group.Read.All, User.Read.All, Contact.Read.All Connect-MgGraph -Scopes "Group.Read.All", "User.Read.All", "Contact.Read.All" $results = @() $groups = Get-MgGroup -All -Property "displayName,id" foreach ($group in $groups) { $members = Get-MgGroupMember -GroupId $group.Id -All -Property "id,oDataType" foreach ($member in $members) { $memberType = $member.ODataType -replace "#microsoft.graph.", "" $memberDetails = $null # 根据类型获取详细信息 switch ($memberType) { "user" { $memberDetails = Get-MgUser -UserId $member.Id -Property "displayName,userPrincipalName,mail,userType" } "group" { $memberDetails = Get-MgGroup -GroupId $member.Id -Property "displayName,description" } "contact" { $memberDetails = Get-MgContact -ContactId $member.Id -Property "displayName,emailAddresses" } } # 组装结果,空值用N/A填充 $resultObj = [PSCustomObject]@{ GroupName = $group.DisplayName GroupId = $group.Id MemberId = $member.Id MemberType = $memberType MemberName = $memberDetails.DisplayName ?? "N/A" UserUPN = if ($memberType -eq "user") { $memberDetails.UserPrincipalName } else { "N/A" } UserMail = if ($memberType -eq "user") { $memberDetails.Mail } else { "N/A" } ContactMail = if ($memberType -eq "contact") { $memberDetails.EmailAddresses[0].Address } else { "N/A" } SubGroupDescription = if ($memberType -eq "group") { $memberDetails.Description } else { "N/A" } } $results += $resultObj } } $results | Export-Csv -Path "C:\scripts\Azure_Groups_Members_Detailed.csv" -NoTypeInformation -Encoding UTF8
注意事项
- 执行脚本前,确保已安装Microsoft Graph PowerShell模块:
Install-Module Microsoft.Graph -Force - 首次连接
Connect-MgGraph时会弹出授权页面,需用有对应读取权限的账号登录 - 导出CSV时用UTF8编码,避免中文乱码
内容的提问来源于stack exchange,提问作者curtiplas
相关产品推荐
相关产品推荐

