You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用Microsoft Graph API获取组用户添加审计日志遇请求错误

问题:查询过去30天内被添加到指定组的用户日志失败

我需要获取过去30天的日志,查询哪些用户被添加到指定组中。用Python执行其他报表和修改操作都正常,唯独这个功能出问题。

我首先尝试用filter选项构造请求:

targetUrl = "https://graph.microsoft.com/v1.0/auditLogs/directoryAudits?$filter=activityDateTime gt 2022-10-08"

但一直收到Bad Request错误。

之后尝试通过TargetResources里的newValue字段过滤,构造了这个请求:

targetUrl = "https://graph.microsoft.com/v1.0/auditLogs/directoryAudits?$filter=targetResources/any(x: startswith(x/newValue, '{value}')"

还是收到Bad Request错误,搞不清问题出在哪。

以下是Microsoft官方示例输出:

"value": [{
        "id": "id",
        "category": "UserManagement",
        "correlationId": "da159bfb-54fa-4092-8a38-6e1fa7870e30",
        "result": "success",
        "resultReason": "Successfully added member to group",
        "activityDisplayName": "Add member to group",
        "activityDateTime": "2018-01-09T21:20:02.7215374Z",
        "loggedByService": "Core Directory",
        "initiatedBy": {
            "user": {
                "id": "728309ae-1a37-4937-9afe-e35d964db09b",
                "displayName": "Audry Oliver",
                "userPrincipalName": "bob@wingtiptoysonline.com",
                "ipAddress": "127.0.0.1"
            },
            "app": null
        },
        "targetResources": [{
            "id": "ef7e527d-6c92-4234-8c6d-cf6fdfb57f95",
            "displayName": "Example.com",
            "Type": "Group",
            "modifiedProperties": [{
                "displayName": "Action Client Name",
                "oldValue": null,
                "newValue": "DirectorySync"}],
            "groupType": "unifiedGroups"
            }, 
            {
            "id": "1f0e98f5-3161-4c6b-9b50-d488572f2bb7",
            "displayName": null,
            "Type": "User",
            "modifiedProperties": [],
            "userPrincipalName": "bob@contoso.com"
        }],
        "additionalDetails": [{
            "key": "Additional Detail Name",
            "value": "Additional Detail Value"
        }]
    }]
}
解决方案

1. 第一个请求的问题

activityDateTime的日期格式需要用单引号包裹,且必须符合ISO 8601格式(带时区标识)。正确写法:

targetUrl = "https://graph.microsoft.com/v1.0/auditLogs/directoryAudits?$filter=activityDateTime gt '2022-10-08T00:00:00Z'"

Graph API要求日期时间值必须用单引号括起来,否则会因解析失败返回Bad Request。

2. 第二个请求的问题

  • 语法不完整:any()表达式缺少闭合括号,结尾需加)
  • newValue并非直接在targetResources对象下,而是嵌套在modifiedProperties数组中,需先遍历该数组才能访问

如果要精准查询指定组的用户添加日志,建议结合activityDisplayName(定位添加成员操作)、目标组ID和时间范围,示例请求:

# 替换{GROUP_ID}为目标组ID,{30_DAYS_AGO}为30天前的ISO格式时间(如'2024-04-20T00:00:00Z')
targetUrl = "https://graph.microsoft.com/v1.0/auditLogs/directoryAudits?$filter=activityDisplayName eq 'Add member to group' and activityDateTime gt '{30_DAYS_AGO}' and targetResources/any(tr: tr/id eq '{GROUP_ID}' and tr/type eq 'Group')"

3. 额外优化建议

  • 用Python自动计算30天前的时间,避免硬编码日期:
from datetime import datetime, timedelta

thirty_days_ago = datetime.utcnow() - timedelta(days=30)
iso_date = thirty_days_ago.isoformat() + 'Z'
# 替换{GROUP_ID}为实际组ID
targetUrl = f"https://graph.microsoft.com/v1.0/auditLogs/directoryAudits?$filter=activityDisplayName eq 'Add member to group' and activityDateTime gt '{iso_date}' and targetResources/any(tr: tr/id eq '{GROUP_ID}' and tr/type eq 'Group')"
  • 若需通过newValue过滤,正确的filter语法需遍历modifiedProperties:
targetUrl = "https://graph.microsoft.com/v1.0/auditLogs/directoryAudits?$filter=targetResources/any(tr: tr/modifiedProperties/any(mp: startswith(mp/newValue, 'DirectorySync')))"

内容的提问来源于stack exchange,提问作者Samu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 01:50:33