You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD动态组配置问题:如何让仅同时属B组与C组集合的用户加入A组

Azure AD动态组规则:筛选同时属于指定多组的用户

完全可行,通过Azure AD动态组的成员规则就能实现你的需求:仅让同时属于Group B,且属于Group Collection C中任意一个组的用户自动加入Group A。

你现有规则的问题分析

  1. 第一条规则:user.memberof -any (group.objectId -in ["GroupC-1Id", "GroupC-2Id"]) -and user.memberof -any (group.objectId -in ["GroupBId"])
    出现仅属于Group C-1的用户被加入,大概率是因为Group B的Object ID填写错误(比如为空、复制时带多余字符),导致-and后的条件未生效,规则实际只筛选了属于C组的用户。

  2. 第二条规则:user.memberof any (group.objectId in ["GroupBId"]) and (user.memberof any (group.objectId eq ["GroupC-1Id"]) or user.memberof any (group.objectId eq ["GroupC-2Id"]))
    出现仅属于Group B的用户被加入,是因为eq运算符只能匹配单个值,你错误地传入了数组["GroupC-1Id"],导致该条件被判定为无效(恒真),最终规则实际只筛选了属于Group B的用户。

正确的规则写法

以下两种写法都能实现你的需求:

写法一:用-in简化多组判断

(user.memberof -any (group.objectId -eq "GroupBId")) -and (user.memberof -any (group.objectId -in ["GroupC-1Id", "GroupC-2Id"]))

写法二:用-eq加-or逐个判断C组

(user.memberof -any (group.objectId -eq "GroupBId")) -and ((user.memberof -any (group.objectId -eq "GroupC-1Id")) -or (user.memberof -any (group.objectId -eq "GroupC-2Id")))

注意事项

  • 务必确认所有组的Object ID完全正确,复制时避免空格、换行或其他多余字符
  • 动态组规则生效存在延迟,配置完成后建议等待15-30分钟再验证成员列表
  • 动态组需要Azure AD Premium P1或P2许可证支持,确保你的租户已满足许可要求

内容的提问来源于stack exchange,提问作者ChasetopherB

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 23:10:30