You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将共享邮箱权限查询出的组对接Get-AzureADGroup展开组成员?

获取共享邮箱及其关联组成员信息的正确方法

需求与问题背景

需要获取所有共享邮箱的列表,并展开每个共享邮箱对应的组成员信息。目前已能通过以下命令获取共享邮箱关联的组信息:

Get-EXOMailbox -RecipientTypeDetails SharedMailbox -ResultSize:Unlimited | Get-MailboxPermission | select *user  | where { ($_.User -Notlike 'NT*' -and $_.User -Notlike '*@*')   }

但需要将上述结果传入Get-AzureADGroup命令以获取组成员,尝试的代码未能正确运行。

原尝试代码(存在问题)

$groupnames = (Get-EXOMailbox -RecipientTypeDetails SharedMailbox -ResultSize:Unlimited | Get-MailboxPermission | select *user  | where { ($_.User -Notlike 'NT*' -and $_.User -Notlike '*@*')   })
    
foreach($item in $groupnames){
   $item
   Get-AzureADGroup -SearchString $item | Get-AzureADGroupMember | Select DisplayName, Mail
}

问题原因

$groupnames存储的是包含User属性的完整对象,而非纯字符串的组名,直接将对象传给Get-AzureADGroup -SearchString会导致参数类型不匹配,该参数需要字符串类型的组名。

正确实现方案

基础版代码

# 提取共享邮箱关联的组名字符串列表
$sharedMailboxGroups = Get-EXOMailbox -RecipientTypeDetails SharedMailbox -ResultSize Unlimited | 
    Get-MailboxPermission | 
    Where-Object { 
        $_.User -notlike 'NT*' -and $_.User -notlike '*@*'
    } |
    Select-Object -ExpandProperty User

# 遍历组名,获取并输出组成员
foreach ($groupName in $sharedMailboxGroups) {
    Write-Host "--- 组: $groupName 的成员 ---"
    Get-AzureADGroup -SearchString $groupName | 
        Get-AzureADGroupMember | 
        Select-Object DisplayName, Mail
}

精确匹配版(推荐)

如果担心SearchString会匹配多个相似组名,可改用过滤条件精确匹配组名,避免返回无关结果:

# 提取共享邮箱关联的组名字符串列表
$sharedMailboxGroups = Get-EXOMailbox -RecipientTypeDetails SharedMailbox -ResultSize Unlimited | 
    Get-MailboxPermission | 
    Where-Object { 
        $_.User -notlike 'NT*' -and $_.User -notlike '*@*'
    } |
    Select-Object -ExpandProperty User

# 遍历组名,精确查找组并获取成员
foreach ($groupName in $sharedMailboxGroups) {
    Write-Host "--- 组: $groupName 的成员 ---"
    $targetGroup = Get-AzureADGroup -Filter "displayName eq '$groupName'"
    if ($targetGroup) {
        $targetGroup | Get-AzureADGroupMember | Select-Object DisplayName, Mail
    } else {
        Write-Warning "未找到对应组: $groupName"
    }
}

关键说明

  • 使用Select-Object -ExpandProperty User提取User属性的纯字符串值,确保Get-AzureADGroup能正确接收参数。
  • 精确匹配的过滤条件"displayName eq '$groupName'"可以避免模糊搜索带来的误匹配问题,提升结果准确性。

内容的提问来源于stack exchange,提问作者Matthew Wilde

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 02:40:17