You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何结合Get-AzPolicyAssignment与Get-AzBlueprintAssignment查询资源组关联策略与蓝图

查看特定Azure资源组的策略与蓝图分配信息

一、Azure门户手动查看方法

查看已应用的Azure Policy

  1. 登录Azure门户,定位到目标资源组
  2. 在左侧导航栏选择策略,切换到分配标签页
  3. 列表会显示直接分配到该资源组的策略,以及从父订阅/管理组继承的策略(可通过「分配范围」列区分)

查看已应用的Azure Blueprint

  1. 登录Azure门户,定位到目标资源组
  2. 在左侧导航栏选择蓝图,切换到已分配的蓝图标签页
  3. 列表中会显示所有将该资源组作为目标的已分配蓝图

二、PowerShell脚本一键查询方案

以下脚本结合Get-AzPolicyAssignment和Get-AzBlueprintAssignment,只需输入资源组名称,即可同时输出对应的策略与蓝图分配信息。

前提条件

  • 已安装Azure PowerShell模块(执行Install-Module -Name Az -AllowClobber -Scope CurrentUser完成安装)
  • 已通过Connect-AzAccount登录Azure账号

脚本代码

# 提示输入目标资源组名称
$resourceGroupName = Read-Host -Prompt "请输入目标资源组名称"

# 获取资源组详细信息(包含订阅ID)
try {
    $resourceGroup = Get-AzResourceGroup -Name $resourceGroupName -ErrorAction Stop
}
catch {
    Write-Error "无法找到资源组 '$resourceGroupName',请检查名称是否正确或权限是否足够"
    exit 1
}

$resourceGroupId = $resourceGroup.ResourceId
$subscriptionId = $resourceGroup.SubscriptionId

Write-Host "`n=== 资源组 '$resourceGroupName' 关联的Azure Policy分配信息 ===" -ForegroundColor Cyan

# 查询资源组相关的Policy分配(包含直接分配和继承的)
$policyAssignments = Get-AzPolicyAssignment -Filter "atScope() or targetResourceId eq '$resourceGroupId'" -SubscriptionId $subscriptionId

if ($policyAssignments) {
    $policyAssignments | Select-Object DisplayName, AssignmentScope, PolicyDefinitionId, CreatedBy, AssignmentState | Format-Table -AutoSize
}
else {
    Write-Host "未找到任何关联的Policy分配" -ForegroundColor Gray
}

Write-Host "`n=== 资源组 '$resourceGroupName' 关联的Azure Blueprint分配信息 ===" -ForegroundColor Cyan

# 查询资源组相关的Blueprint分配
$blueprintAssignments = Get-AzBlueprintAssignment -Scope "/subscriptions/$subscriptionId/resourceGroups/$resourceGroupName"

if ($blueprintAssignments) {
    $blueprintAssignments | Select-Object Name, BlueprintName, Scope, ProvisioningState, CreatedBy | Format-Table -AutoSize
}
else {
    Write-Host "未找到任何关联的Blueprint分配" -ForegroundColor Gray
}

脚本说明

  1. 资源组验证:先通过Get-AzResourceGroup确认资源组存在,避免后续命令报错
  2. Policy查询逻辑:使用Filter参数筛选出直接作用于资源组(targetResourceId eq '$resourceGroupId')以及从上级范围继承(atScope())的策略分配
  3. Blueprint查询逻辑:通过指定资源组的完整范围路径,精准查询针对该资源组的蓝图分配
  4. 格式化输出:仅展示关键字段,让结果更易读

内容的提问来源于stack exchange,提问作者Senior Systems Engineer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 14:35:23