You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Kusto获取用户Azure AD组成员身份列表?

获取当前用户所属Azure AD组的动态数组列表(Kusto查询)

要动态生成当前用户所属Azure AD组的数组格式列表(如["XXXX","YYYY","ZZZZ"]),可以利用Kusto的directory()函数查询Azure AD目录数据,结合用户身份过滤后生成目标格式。

基础实现(精确匹配组成员)

以下查询会返回当前用户所属的所有AD组,并将组名汇总为数组,避免部分匹配导致的误判:

directory()
| where Type == "Group"  // 筛选AD组对象
// 通过集合交集精确判断当前用户是否为组成员
| where array_length(set_intersection(members, dynamic([current_principal()]))) > 0
| summarize UserGroups = make_list(displayName)  // 将组名汇总为数组格式

简化写法(适用于无重复UPN前缀场景)

如果租户内不存在用户UPN前缀重复的情况,可使用更简洁的判断逻辑:

directory()
| where Type == "Group"
| where members contains current_principal()
| summarize UserGroups = make_list(displayName)

在后续查询中复用该列表

可以将生成的组列表定义为变量,直接用于后续的数据过滤逻辑:

// 预生成当前用户的组列表变量
let userGroups = directory()
| where Type == "Group"
| where array_length(set_intersection(members, dynamic([current_principal()]))) > 0
| summarize make_list(displayName);

// 后续查询示例:筛选与用户组匹配的业务数据
your_target_table
| where GroupNameColumn in (userGroups)

注意事项

  • 执行查询的用户需要具备读取Azure AD目录数据的权限,以及Kusto集群的directory()函数使用权限;
  • directory()函数返回当前租户内的Azure AD对象,包含组的displayName(显示名称)和members(成员列表,格式为动态数组);
  • current_principal()返回当前执行查询的用户UPN,与members数组中的值直接匹配。

内容的提问来源于stack exchange,提问作者Matt Douhan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 08:05:15