You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何查询Azure Active Directory中用户账号的禁用时间?

查询Azure AD用户账号的禁用时间/最后修改时间方法

一、优先获取禁用时间

Azure AD没有直接存储"禁用时间"属性,但可以通过审核日志检索用户被禁用的操作记录,禁用账号的操作会被标记为Disable account事件:

使用Azure AD PowerShell模块查询

# 替换<用户ObjectID>为目标用户的Object ID
Get-AzureADAuditDirectoryLogs -Filter "OperationName eq 'Disable account' and TargetResources/any(t: t/id eq '<用户ObjectID>')" | Select-Object CreatedDateTime, OperationName, InitiatedBy, TargetResources
  • 结果中的CreatedDateTime即为用户被禁用的时间,若用户多次被禁用会返回多条记录,取最新的一条即可。
  • 注意:审核日志默认保留90天,超过期限的记录无法查询。

二、获取最后修改时间(替代方案)

如果无法通过审核日志获取禁用时间,可以获取用户对象的最后修改时间LastModifiedDateTime,该属性会在用户任何属性(包括禁用状态)变更时更新:

方法1:Azure AD PowerShell模块

# 替换<用户ObjectID>为目标用户的Object ID
Get-AzureADUser -ObjectId "<用户ObjectID>" | Select-Object ObjectId, UserPrincipalName, LastModifiedDateTime

方法2:Microsoft Graph PowerShell模块(推荐)

# 若未安装模块,先执行:Install-Module Microsoft.Graph -Scope CurrentUser
# 导入模块:Import-Module Microsoft.Graph.Users

# 替换<用户ObjectID>为目标用户的Object ID
Get-MgUser -UserId "<用户ObjectID>" -Property Id, UserPrincipalName, LastModifiedDateTime | Select-Object Id, UserPrincipalName, LastModifiedDateTime

内容的提问来源于stack exchange,提问作者hello007

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 22:31:15