如何用PowerShell检查Azure AD应用的IdentifierUris是否存在?
I get it—you already have logic to check for an existing app by display name, but need to add validation for the IdentifierUris since that value has to be globally unique across Azure AD. Let's fix that.
First, the key here is using the -Filter parameter with Get-AzADApplication to query for apps that already use your target URI. Azure AD supports OData filters for this, and since identifierUris is a collection, we can use the any operator to check if the URI exists in any app's identifier list.
Here's the revised script with both checks (display name and IdentifierUris) included, plus fixes for the original script's minor error:
$appName = "data-factory-app" $appURI = "www.datafactoryapp.com" # Check for existing app by display name $existingAppByName = Get-AzADApplication -DisplayName $appName # Check for any app using the target IdentifierUri via OData filter $existingAppByUri = Get-AzADApplication -Filter "identifierUris/any(u: u eq '$appURI')" if (-not $existingAppByName -and -not $existingAppByUri) { # Create the app only if neither the name nor URI is in use New-AzADApplication -DisplayName $appName -IdentifierUris $appURI Write-Output "Successfully created the application: $appName" } else { # Provide specific feedback on what already exists if ($existingAppByName) { Write-Output "An application with display name '$appName' already exists in your tenant." } if ($existingAppByUri) { Write-Output "An application with IdentifierUri '$appURI' is already in use by another app." } }
A few notes on this approach:
- OData Filter Efficiency: Using
-Filterdirectly queries Azure AD instead of fetching all apps and filtering locally, which is much faster especially if your tenant has many applications. - Global Uniqueness:
IdentifierUrismust be unique across all Azure AD tenants (not just yours), so this check prevents you from hitting creation errors due to duplicate URIs. - Clear Feedback: The script now tells you exactly which conflict exists—either the display name or the URI—instead of a generic message.
Also, I noticed your original script had a typo where you tried accessing $appExists.IdentifierUris when $appExists was null (since -not $appExists was true). That would have thrown an error, so the revised script avoids that by separating the two checks entirely.
内容的提问来源于stack exchange,提问作者3355307

