You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何列出所有Azure Service Bus共享访问策略?KQL或Dotnet可行吗?

获取Azure Service Bus所有共享访问策略的方法

方法一:使用KQL(Azure Resource Graph)

通过Azure Resource Graph的KQL查询可批量获取跨订阅/资源组的Service Bus共享访问策略,适合批量排查场景:

Resources
| where type == "Microsoft.ServiceBus/namespaces/authorizationRules"
| project
    SubscriptionId,
    ResourceGroup,
    NamespaceName = split(id, '/')[8],
    PolicyName = name,
    Rights = properties.rights
| order by ResourceGroup, NamespaceName

说明:

  • 查询返回所有订阅内Service Bus命名空间的策略详情,包含所属订阅ID、资源组、命名空间名、策略名及权限(如Send/Listen/Manage)。
  • 可添加| where subscriptionId == "<目标订阅ID>"限定查询范围。

方法二:使用.NET SDK

通过Azure Resource Manager的Service Bus SDK编程获取,步骤如下:

1. 安装NuGet包

Install-Package Azure.ResourceManager.ServiceBus

2. 示例代码

using Azure.Identity;
using Azure.ResourceManager;
using Azure.ResourceManager.ServiceBus;

var armClient = new ArmClient(new DefaultAzureCredential());

// 遍历所有订阅(可替换为指定订阅ID)
await foreach (var subscription in armClient.GetSubscriptionsAsync())
{
    await foreach (var resourceGroup in subscription.GetResourceGroupsAsync())
    {
        // 获取资源组下所有Service Bus命名空间
        await foreach (var namespaceResource in resourceGroup.GetServiceBusNamespacesAsync())
        {
            Console.WriteLine($"命名空间: {namespaceResource.Data.Name}");
            // 获取该命名空间下所有共享访问策略
            await foreach (var authRule in namespaceResource.GetServiceBusNamespaceAuthorizationRulesAsync())
            {
                Console.WriteLine($"  策略名称: {authRule.Data.Name}, 权限: {string.Join(", ", authRule.Data.Rights)}");
            }
        }
    }
}

说明:

  • DefaultAzureCredential自动从环境变量、Azure CLI、Visual Studio等渠道获取身份凭证,适配本地开发与生产环境。
  • 若需限定特定订阅或资源组,可直接获取对应对象,无需全量遍历。

内容的提问来源于stack exchange,提问作者Muhammad Naveed Younus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 04:55:29