You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求Azure AD与本地AD同步环境下快速撤销全局管理员权限的脚本

针对同步环境下Azure AD全局管理员的权限撤销脚本

前提条件

  • 拥有特权角色管理员或另一个全局管理员权限的账号
  • 已安装Microsoft Graph PowerShell模块:Install-Module Microsoft.Graph -Force -AllowClobber
  • 注意:由于Azure AD与本地AD同步,本地AD同步过来的组无法直接在Azure AD移除成员身份,需同步处理本地AD操作

步骤1:查询目标用户的所有角色与组成员身份

先运行以下脚本获取用户的完整权限信息:

# 连接到Microsoft Graph
Connect-MgGraph -Scopes "RoleManagement.Read.Directory", "Group.Read.All", "User.Read.All"

# 定义目标用户的UPN或Object ID
$targetUserUpn = "user@contoso.com"
$targetUser = Get-MgUser -UserId $targetUserUpn

# 查询用户的Azure AD角色分配
Write-Host "=== 目标用户的Azure AD角色分配 ==="
Get-MgRoleManagementDirectoryRoleAssignment -Filter "principalId eq '$($targetUser.Id)'" | Select-Object RoleDefinitionId, PrincipalId, @{Name='RoleName'; Expression={(Get-MgRoleManagementDirectoryRoleDefinition -RoleDefinitionId $_.RoleDefinitionId).DisplayName}}

# 查询用户的组成员身份(区分同步组和云原生组)
Write-Host "`n=== 目标用户的组成员身份 ==="
Get-MgMemberOf -UserId $targetUser.Id -All $true | ForEach-Object {
    $group = Get-MgGroup -GroupId $_.Id
    $isSynced = if ($group.OnPremisesSyncEnabled -eq $true) { "是(需在本地AD处理)" } else { "否(云原生组)" }
    [PSCustomObject]@{
        GroupName = $group.DisplayName
        GroupId = $group.Id
        IsSyncedFromOnPrem = $isSynced
    }
}

步骤2:移除目标用户的所有角色与云组身份

确认信息后,运行以下脚本移除Azure AD角色和云原生组的成员身份:

# 重新连接(若会话已过期)
Connect-MgGraph -Scopes "RoleManagement.ReadWrite.Directory", "Group.ReadWrite.All", "User.Read.All"

$targetUserUpn = "user@contoso.com"
$targetUser = Get-MgUser -UserId $targetUserUpn

# 移除所有Azure AD角色分配
Write-Host "=== 移除Azure AD角色分配 ==="
Get-MgRoleManagementDirectoryRoleAssignment -Filter "principalId eq '$($targetUser.Id)'" | ForEach-Object {
    Remove-MgRoleManagementDirectoryRoleAssignment -UnifiedRoleAssignmentId $_.Id
    Write-Host "已移除角色:$(Get-MgRoleManagementDirectoryRoleDefinition -RoleDefinitionId $_.RoleDefinitionId).DisplayName"
}

# 移除云原生组的成员身份
Write-Host "`n=== 移除云原生组成员身份 ==="
Get-MgMemberOf -UserId $targetUser.Id -All $true | ForEach-Object {
    $group = Get-MgGroup -GroupId $_.Id
    if ($group.OnPremisesSyncEnabled -ne $true) {
        Remove-MgGroupMemberByRef -GroupId $group.Id -DirectoryObjectId $targetUser.Id
        Write-Host "已移除组:$($group.DisplayName)"
    } else {
        Write-Host "跳过同步组:$($group.DisplayName)(需在本地AD处理)"
    }
}

步骤3:处理本地AD同步组的成员身份

对于查询结果中标记为“需在本地AD处理”的组,在本地AD服务器上运行以下PowerShell脚本移除用户:

# 定义目标用户的SamAccountName
$targetSamAccountName = "username"
$targetUser = Get-ADUser -Identity $targetSamAccountName

# 获取用户的所有本地AD组并移除成员身份
Get-ADPrincipalGroupMembership -Identity $targetUser | ForEach-Object {
    Remove-ADGroupMember -Identity $_.DistinguishedName -Members $targetUser -Confirm:$false
    Write-Host "已从本地AD组移除:$($_.Name)"
}

关键注意事项

  • 运行脚本前务必确认目标用户信息,避免误操作
  • 全局管理员角色移除后,确保仍有其他全局管理员账号可用,防止锁死
  • 本地AD操作后,等待Azure AD同步(默认30分钟,可手动触发同步)完成后,权限才会完全撤销

内容的提问来源于stack exchange,提问作者G-P2P G

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 12:01:02