求Azure AD与本地AD同步环境下快速撤销全局管理员权限的脚本
针对同步环境下Azure AD全局管理员的权限撤销脚本
前提条件
- 拥有特权角色管理员或另一个全局管理员权限的账号
- 已安装Microsoft Graph PowerShell模块:
Install-Module Microsoft.Graph -Force -AllowClobber - 注意:由于Azure AD与本地AD同步,本地AD同步过来的组无法直接在Azure AD移除成员身份,需同步处理本地AD操作
步骤1:查询目标用户的所有角色与组成员身份
先运行以下脚本获取用户的完整权限信息:
# 连接到Microsoft Graph Connect-MgGraph -Scopes "RoleManagement.Read.Directory", "Group.Read.All", "User.Read.All" # 定义目标用户的UPN或Object ID $targetUserUpn = "user@contoso.com" $targetUser = Get-MgUser -UserId $targetUserUpn # 查询用户的Azure AD角色分配 Write-Host "=== 目标用户的Azure AD角色分配 ===" Get-MgRoleManagementDirectoryRoleAssignment -Filter "principalId eq '$($targetUser.Id)'" | Select-Object RoleDefinitionId, PrincipalId, @{Name='RoleName'; Expression={(Get-MgRoleManagementDirectoryRoleDefinition -RoleDefinitionId $_.RoleDefinitionId).DisplayName}} # 查询用户的组成员身份(区分同步组和云原生组) Write-Host "`n=== 目标用户的组成员身份 ===" Get-MgMemberOf -UserId $targetUser.Id -All $true | ForEach-Object { $group = Get-MgGroup -GroupId $_.Id $isSynced = if ($group.OnPremisesSyncEnabled -eq $true) { "是(需在本地AD处理)" } else { "否(云原生组)" } [PSCustomObject]@{ GroupName = $group.DisplayName GroupId = $group.Id IsSyncedFromOnPrem = $isSynced } }
步骤2:移除目标用户的所有角色与云组身份
确认信息后,运行以下脚本移除Azure AD角色和云原生组的成员身份:
# 重新连接(若会话已过期) Connect-MgGraph -Scopes "RoleManagement.ReadWrite.Directory", "Group.ReadWrite.All", "User.Read.All" $targetUserUpn = "user@contoso.com" $targetUser = Get-MgUser -UserId $targetUserUpn # 移除所有Azure AD角色分配 Write-Host "=== 移除Azure AD角色分配 ===" Get-MgRoleManagementDirectoryRoleAssignment -Filter "principalId eq '$($targetUser.Id)'" | ForEach-Object { Remove-MgRoleManagementDirectoryRoleAssignment -UnifiedRoleAssignmentId $_.Id Write-Host "已移除角色:$(Get-MgRoleManagementDirectoryRoleDefinition -RoleDefinitionId $_.RoleDefinitionId).DisplayName" } # 移除云原生组的成员身份 Write-Host "`n=== 移除云原生组成员身份 ===" Get-MgMemberOf -UserId $targetUser.Id -All $true | ForEach-Object { $group = Get-MgGroup -GroupId $_.Id if ($group.OnPremisesSyncEnabled -ne $true) { Remove-MgGroupMemberByRef -GroupId $group.Id -DirectoryObjectId $targetUser.Id Write-Host "已移除组:$($group.DisplayName)" } else { Write-Host "跳过同步组:$($group.DisplayName)(需在本地AD处理)" } }
步骤3:处理本地AD同步组的成员身份
对于查询结果中标记为“需在本地AD处理”的组,在本地AD服务器上运行以下PowerShell脚本移除用户:
# 定义目标用户的SamAccountName $targetSamAccountName = "username" $targetUser = Get-ADUser -Identity $targetSamAccountName # 获取用户的所有本地AD组并移除成员身份 Get-ADPrincipalGroupMembership -Identity $targetUser | ForEach-Object { Remove-ADGroupMember -Identity $_.DistinguishedName -Members $targetUser -Confirm:$false Write-Host "已从本地AD组移除:$($_.Name)" }
关键注意事项
- 运行脚本前务必确认目标用户信息,避免误操作
- 全局管理员角色移除后,确保仍有其他全局管理员账号可用,防止锁死
- 本地AD操作后,等待Azure AD同步(默认30分钟,可手动触发同步)完成后,权限才会完全撤销
内容的提问来源于stack exchange,提问作者G-P2P G
相关产品推荐
相关产品推荐

