如何查询Azure Active Directory中用户账号的禁用时间?
查询Azure AD用户账号的禁用时间/最后修改时间方法
一、优先获取禁用时间
Azure AD没有直接存储"禁用时间"属性,但可以通过审核日志检索用户被禁用的操作记录,禁用账号的操作会被标记为Disable account事件:
使用Azure AD PowerShell模块查询
# 替换<用户ObjectID>为目标用户的Object ID Get-AzureADAuditDirectoryLogs -Filter "OperationName eq 'Disable account' and TargetResources/any(t: t/id eq '<用户ObjectID>')" | Select-Object CreatedDateTime, OperationName, InitiatedBy, TargetResources
- 结果中的
CreatedDateTime即为用户被禁用的时间,若用户多次被禁用会返回多条记录,取最新的一条即可。 - 注意:审核日志默认保留90天,超过期限的记录无法查询。
二、获取最后修改时间(替代方案)
如果无法通过审核日志获取禁用时间,可以获取用户对象的最后修改时间LastModifiedDateTime,该属性会在用户任何属性(包括禁用状态)变更时更新:
方法1:Azure AD PowerShell模块
# 替换<用户ObjectID>为目标用户的Object ID Get-AzureADUser -ObjectId "<用户ObjectID>" | Select-Object ObjectId, UserPrincipalName, LastModifiedDateTime
方法2:Microsoft Graph PowerShell模块(推荐)
# 若未安装模块,先执行:Install-Module Microsoft.Graph -Scope CurrentUser # 导入模块:Import-Module Microsoft.Graph.Users # 替换<用户ObjectID>为目标用户的Object ID Get-MgUser -UserId "<用户ObjectID>" -Property Id, UserPrincipalName, LastModifiedDateTime | Select-Object Id, UserPrincipalName, LastModifiedDateTime
内容的提问来源于stack exchange,提问作者hello007
相关产品推荐
相关产品推荐

