You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于REST API获取Azure DevOps(TFS)用户安全组的PowerShell脚本

PowerShell脚本实现(适配Azure DevOps及本地TFS)

以下脚本支持传入用户邮箱/用户名作为入参,自动调用REST API拉取指定用户所属的全部安全组(包含嵌套组继承的成员关系),云版Azure DevOps、本地部署TFS均兼容。

前置要求

  • 执行账号持有目标Azure DevOps组织/TFS集合的安全读取权限
  • 提前准备个人访问令牌(PAT),令牌需开通Identity (Read)、Security (Read)、Project and Team (Read)权限范围

完整脚本

param(
    [Parameter(Mandatory=$true)]
    [string]$OrganizationUrl,
    [Parameter(Mandatory=$true)]
    [string]$UserIdentifier,
    [Parameter(Mandatory=$true)]
    [string]$Pat
)

# 构造鉴权请求头
$base64AuthInfo = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes(":$($Pat)"))
$headers = @{
    Authorization = "Basic $base64AuthInfo"
    "Content-Type" = "application/json"
}

# 匹配目标用户,获取用户身份描述符
$searchUserApi = "$OrganizationUrl/_apis/identities?searchFilter=General&filterValue=$([Uri]::EscapeDataString($UserIdentifier))&queryMembership=None&api-version=7.1-preview.1"
try {
    $userResp = Invoke-RestMethod -Uri $searchUserApi -Method Get -Headers $headers -ErrorAction Stop
}
catch {
    Write-Error "用户查询失败:$($_.Exception.Message)"
    exit 1
}

if (-not $userResp.value -or $userResp.value.Count -eq 0) {
    Write-Error "未找到与标识 $UserIdentifier 匹配的用户,请核对输入"
    exit 1
}
$targetUser = $userResp.value[0]
Write-Host "匹配到目标用户:$($targetUser.providerDisplayName),关联账号:$($targetUser.properties.Account.'$value')" -ForegroundColor Green

# 查询用户所有所属组(含嵌套组向上追溯)
$membershipApi = "$OrganizationUrl/_apis/identities/$($targetUser.descriptor)/memberships?direction=Up&api-version=7.1-preview.1"
try {
    $membershipResp = Invoke-RestMethod -Uri $membershipApi -Method Get -Headers $headers -ErrorAction Stop
}
catch {
    Write-Error "组成员关系查询失败:$($_.Exception.Message)"
    exit 1
}

# 拉取组详情并格式化输出
$result = @()
foreach ($member in $membershipResp.value) {
    $groupApi = "$OrganizationUrl/_apis/identities/$($member.containerDescriptor)?api-version=7.1-preview.1"
    $groupInfo = Invoke-RestMethod -Uri $groupApi -Method Get -Headers $headers
    $result += [PSCustomObject]@{
        组名称 = $groupInfo.providerDisplayName
        组描述 = if ($groupInfo.description) { $groupInfo.description } else { "无描述" }
        所属范围 = if ($groupInfo.properties.ScopeName) { $groupInfo.properties.ScopeName.'$value' } else { "组织全局" }
        类别 = if ($groupInfo.isTeam) { "项目团队" } else { "安全组" }
    }
}

Write-Host "`n共查询到用户所属组/团队 $($result.Count) 个:" -ForegroundColor Cyan
$result | Format-Table -AutoSize
return $result

使用方法

  • 云版Azure DevOps调用示例:
    .\Get-UserAdGroups.ps1 -OrganizationUrl "https://dev.azure.com/你的组织名称" -UserIdentifier "user@yourcorp.com" -Pat "你生成的PAT令牌"
    
  • 本地TFS调用示例:
    .\Get-UserAdGroups.ps1 -OrganizationUrl "http://你的TFS服务地址/tfs/目标集合名称" -UserIdentifier "域\用户名" -Pat "你生成的PAT令牌"
    

注意:如果搜索用户时出现重名匹配错误,可自行修改脚本中用户匹配逻辑,增加工号、域账号等精确匹配规则即可。

内容的提问来源于stack exchange,提问作者noamsh88

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.30 20:03:23