Azure DevOps部署因AD配额超限失败,PowerShell命令执行报错求助
问题场景
Azure Pipeline部署时触发配额错误:
Failed to create an app in Azure Active Directory. Error: The directory object quota limit for the Principal has been exceeded. Please ask your administrator to increase the quota limit or delete objects to reduce the used quota.
尝试执行PowerShell清理命令时失败:
Get-AzureADDeletedApplication: The term 'Get-AzureADDeletedApplication' is not recognized as a name of a cmdlet, function, script file, or executable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try again.
命令失效原因
Get-AzureADDeletedApplication属于AzureAD PowerShell模块,若未安装该模块或模块版本过旧,就会出现此错误。以下直接提供Azure CLI替代方案,无需额外安装模块。
Azure CLI清理操作步骤
1. 登录Azure CLI
确保已安装Azure CLI,执行登录命令:
az login
登录后选择目标租户(若存在多个租户)。
2. 清理已删除的应用程序
列出所有软删除的应用程序
az ad app list --show-deleted --all
批量永久删除软删除的应用程序
在PowerShell中执行以下脚本:
$deletedApps = az ad app list --show-deleted --all --query "[].appId" | ConvertFrom-Json foreach ($app in $deletedApps) { az ad app delete --id $app --force }
3. 清理已删除的服务主体
若配额超限源于服务主体,可同步清理:
列出所有软删除的服务主体
az ad sp list --show-deleted --all
批量永久删除软删除的服务主体
在PowerShell中执行以下脚本:
$deletedSPs = az ad sp list --show-deleted --all --query "[].id" | ConvertFrom-Json foreach ($sp in $deletedSPs) { az ad sp delete --id $sp --force }
权限说明
执行以上命令需要Azure AD应用程序管理员或全局管理员权限。
验证与后续操作
清理完成后,可通过以下命令查看当前应用/服务主体数量,确认配额释放:
# 查看应用总数 az ad app list --all | Measure-Object # 查看服务主体总数 az ad sp list --all | Measure-Object
之后重新尝试Azure Pipeline部署即可。
内容的提问来源于stack exchange,提问作者Ribo01

