You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将Azure AD中现有用户的所有组分配给新用户?

批量复制Azure AD用户的组成员身份到新用户

你可以通过以下几种方式实现批量添加,无需逐个操作:

方法1:使用Microsoft Graph PowerShell(推荐,AzureAD模块已进入弃用周期)

这是目前微软推荐的PowerShell工具,步骤如下:

# 安装Microsoft Graph模块(首次使用时执行)
Install-Module Microsoft.Graph -Scope CurrentUser -Force

# 连接到Microsoft Graph,需授权用户读取和组写入权限
Connect-MgGraph -Scopes "User.Read.All", "GroupMember.ReadWrite.All"

# 替换为实际的源用户和目标用户UPN(或用户ID)
$sourceUserUpn = "source.user@yourdomain.com"
$targetUserUpn = "new.user@yourdomain.com"

# 获取源用户所属的所有组(排除非组类型的目录对象)
$sourceGroups = Get-MgUserMemberOf -UserId $sourceUserUpn | Where-Object {
    $_.AdditionalProperties.'@odata.type' -eq '#microsoft.graph.group'
}

# 获取目标用户的ID
$targetUserId = (Get-MgUser -UserId $targetUserUpn).Id

# 遍历组并添加目标用户
foreach ($group in $sourceGroups) {
    try {
        New-MgGroupMember -GroupId $group.Id -DirectoryObjectId $targetUserId
        Write-Host "✅ 已添加目标用户到组: $($group.DisplayName)"
    }
    catch {
        Write-Host "❌ 添加到组 $($group.DisplayName) 失败: $_"
    }
}

方法2:使用Azure AD PowerShell模块(兼容旧环境)

如果你的环境仍在使用即将弃用的AzureAD模块,可以用以下脚本:

# 安装AzureAD模块(首次使用时执行)
Install-Module AzureAD -Scope CurrentUser -Force

# 连接到Azure AD
Connect-AzureAD

# 替换为实际的源用户和目标用户UPN
$sourceUserUpn = "source.user@yourdomain.com"
$targetUserUpn = "new.user@yourdomain.com"

# 获取源用户所属的所有组
$sourceGroups = Get-AzureADUserMembership -ObjectId $sourceUserUpn | Where-Object {
    $_.ObjectType -eq "Group"
}

# 获取目标用户对象
$targetUser = Get-AzureADUser -Filter "UserPrincipalName eq '$targetUserUpn'"

# 遍历组并添加目标用户
foreach ($group in $sourceGroups) {
    try {
        Add-AzureADGroupMember -ObjectId $group.ObjectId -RefObjectId $targetUser.ObjectId
        Write-Host "✅ 已添加目标用户到组: $($group.DisplayName)"
    }
    catch {
        Write-Host "❌ 添加到组 $($group.DisplayName) 失败: $_"
    }
}

方法3:使用Microsoft Graph API批量请求

如果你偏好API操作,可以构造批量请求一次性完成添加:

  1. 获取源用户的组列表:
    发送GET请求:

    GET https://graph.microsoft.com/v1.0/users/{source-user-id}/memberOf/microsoft.graph.group
    
  2. 构造批量添加请求:
    发送POST请求到https://graph.microsoft.com/v1.0/$batch,请求体示例:

    {
      "requests": [
        {
          "id": "1",
          "method": "POST",
          "url": "/groups/{group-id-1}/members/$ref",
          "body": { "@odata.id": "https://graph.microsoft.com/v1.0/users/{target-user-id}" },
          "headers": { "Content-Type": "application/json" }
        },
        {
          "id": "2",
          "method": "POST",
          "url": "/groups/{group-id-2}/members/$ref",
          "body": { "@odata.id": "https://graph.microsoft.com/v1.0/users/{target-user-id}" },
          "headers": { "Content-Type": "application/json" }
        }
        // 依次添加所有需要同步的组请求
      ]
    }
    

注意事项

  • 执行操作的账号必须拥有GroupMember.ReadWrite.All和User.Read.All权限;
  • 动态组无法手动添加成员,若源用户属于动态组,目标用户需满足该组的动态规则才能自动加入;
  • 建议先选取少量组测试脚本,确认无误后再批量执行。

内容的提问来源于stack exchange,提问作者Navid2132

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 19:30:48