如何通过PowerShell为Intune Windows 10端点安全策略分配组?
使用PowerShell为Intune端点安全策略分配组
前提准备
- 拿到调用
createInstance后返回的策略实例ID(对应deviceManagementIntent或deviceManagementPolicy的ID,取决于你创建的模板类型) - 准备好要分配的Azure AD组ID(可通过
Get-AzureADGroup或Graph API查询获取) - 确保账号拥有
DeviceManagementConfiguration.ReadWrite.All的Graph API权限
步骤1:获取Graph API访问令牌
用交互式登录方式获取令牌(也可以用服务主体登录,根据你的场景选择):
# 交互式登录获取令牌,使用公共Intune客户端ID $token = (Get-MsalToken -ClientId "d1ddf0e4-d672-4dae-b554-9d5bdfd93547" -Scopes "https://graph.microsoft.com/.default" -Interactive).AccessToken
步骤2:构造分配请求体
根据组分配需求构造JSON请求体,支持包含或排除组:
# 构造组分配请求体(示例为包含指定组) $assignmentBody = @{ assignments = @( @{ target = @{ "@odata.type" = "#microsoft.graph.groupAssignmentTarget" groupId = "替换为你的目标组ID" } # 如果需要过滤设备,可添加filter字段,这里用所有设备过滤 intentFilter = @{ "@odata.type" = "#microsoft.graph.allDevicesAssignmentFilter" } } ) } | ConvertTo-Json -Depth 10
步骤3:发送分配请求
根据策略类型选择对应的Graph端点:
针对Windows安全基线(deviceManagementIntent类型)
$intentId = "替换为你的策略实例ID" $assignEndpoint = "https://graph.microsoft.com/beta/deviceManagementIntent/$intentId/assignments" Invoke-RestMethod -Uri $assignEndpoint -Method Post -Headers @{Authorization = "Bearer $token"} -Body $assignmentBody -ContentType "application/json"
针对磁盘加密等独立端点安全策略(deviceManagementPolicy类型)
$policyId = "替换为你的策略实例ID" $assignEndpoint = "https://graph.microsoft.com/beta/deviceManagementPolicy/$policyId/assignments" Invoke-RestMethod -Uri $assignEndpoint -Method Post -Headers @{Authorization = "Bearer $token"} -Body $assignmentBody -ContentType "application/json"
验证分配结果
发送GET请求查看已配置的分配:
Invoke-RestMethod -Uri $assignEndpoint -Method Get -Headers @{Authorization = "Bearer $token"}
内容的提问来源于stack exchange,提问作者CLiFoS
相关产品推荐
相关产品推荐

