You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Get-AzureADGroup与Get-AzureADMSGroup返回结果缺失CommonName属性问题

可行解决方案如下:

  1. 属性映射说明
    MSOL模块返回的CommonName属性,在Azure AD Graph(AzureAD、AzureADMS模块底层调用的接口)中对应同步组的onPremisesCommonName扩展属性,默认不会随Get-AzureADGroup的默认返回字段展示,会存储在返回对象的ExtensionProperty字典字段中。

  2. 直接适配现有AzureAD模块的方法

  • 如果你需要拉取所有组并带出CommonName字段,可以用如下语法构造自定义属性:
Get-AzureADGroup -All $true | Select-Object DisplayName, ObjectId, `
@{Name = 'CommonName'; Expression = { $_.ExtensionProperty.onPremisesCommonName }}
  • 如果你需要按CommonName搜索匹配组,直接用过滤语句即可,效率远高于拉全量后过滤:
# 替换为你要查询的CommonName值
$targetCN = "你的目标组CommonName"
$existGroup = Get-AzureADGroup -Filter "onPremisesCommonName eq '$targetCN'"

如果$existGroup返回非空则表示对应组存在,完全可以匹配你原有的校验逻辑。

  1. 长期兼容方案
    目前MSOL、AzureAD模块都已经被微软标记为弃用状态,后续会逐步停止支持,推荐迁移到最新的Microsoft Graph PowerShell模块,原生支持MFA,且字段定义更清晰,查询CommonName的语法如下:
# 先安装Graph模块,首次运行需要执行
Install-Module Microsoft.Graph -Scope CurrentUser
# 连接时指定组读权限
Connect-MgGraph -Scopes "Group.Read.All"
# 按CommonName查询组
$targetCN = "你的目标组CommonName"
$existGroup = Get-MgGroup -Filter "onPremisesCommonName eq '$targetCN'" -Property onPremisesCommonName,DisplayName,Id

注意:只有从本地AD同步到AAD的组才会有onPremisesCommonName属性,纯云端创建的组本身没有该属性,属于正常现象。

内容的提问来源于stack exchange,提问作者Marcus Hanikat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.30 05:42:03