PowerShell脚本调用Azure Automation解除分配VM报错AADSTS1002016求改写
解决方案
修改后的AzureRm模块脚本
在脚本开头添加强制启用TLS 1.2的配置,确保连接Azure AD时使用符合要求的加密协议:
# 强制启用TLS 1.2 [Net.ServicePointManager]::SecurityProtocol = [Net.ServicePointManager]::SecurityProtocol -bor [Net.SecurityProtocolType]::Tls12 $clientID = "..." $key = "..." $SecurePassword = $key | ConvertTo-SecureString -AsPlainText -Force $cred = New-Object -TypeName System.Management.Automation.PSCredential -ArgumentList $clientID, $SecurePassword Add-AzureRmAccount -Credential $cred -Tenant "..." -ServicePrincipal $params = @{"RESOURCEGROUPNAME" = "..."; "VMNAME" = $env:computername} Start-AzureRmAutomationRunbook -ResourceGroupName "..." -AutomationAccountName "..." -Name "StopAzureV2Vm" -Parameters $params
推荐:迁移到Az模块(AzureRm已弃用)
由于AzureRm模块已停止维护,建议迁移至Az模块,对应的脚本如下:
# 强制启用TLS 1.2 [Net.ServicePointManager]::SecurityProtocol = [Net.ServicePointManager]::SecurityProtocol -bor [Net.SecurityProtocolType]::Tls12 $clientID = "..." $key = "..." $SecurePassword = $key | ConvertTo-SecureString -AsPlainText -Force $cred = New-Object -TypeName System.Management.Automation.PSCredential -ArgumentList $clientID, $SecurePassword Connect-AzAccount -Credential $cred -Tenant "..." -ServicePrincipal $params = @{"RESOURCEGROUPNAME" = "..."; "VMNAME" = $env:computername} Start-AzAutomationRunbook -ResourceGroupName "..." -AutomationAccountName "..." -Name "StopAzureV2Vm" -Parameters $params
关键修改说明
- 添加TLS 1.2强制配置:解决Azure AD对旧版加密协议的禁用限制,确保连接请求符合安全要求。
- Az模块适配:将AzureRm系列命令替换为Az模块对应命令,避免因旧模块停止维护带来的后续问题。
内容的提问来源于stack exchange,提问作者Helloworld
相关产品推荐
相关产品推荐

