使用PowerShell导出带所有者与成员规则的动态Azure AD安全组
PowerShell 导出符合要求的Azure AD组信息操作步骤
- 前置依赖:微软官方已弃用旧AzureAD模块,推荐使用Microsoft Graph PowerShell模块完成操作
安装所需PowerShell模块
执行以下命令安装Groups相关模块,已安装可跳过:Install-Module Microsoft.Graph.Groups -Scope CurrentUser -Force连接Microsoft Graph接口
执行连接命令,需使用拥有Azure AD读取权限的账号登录:Connect-MgGraph -Scopes "Group.Read.All", "Directory.Read.All"执行导出脚本
完整脚本如下,你可以修改$exportPath变量为你实际的CSV导出路径:
# 定义CSV导出路径 $exportPath = "C:\Temp\DynamicSecurityGroups.csv" # 查询符合条件的组:安全组、动态成员类型 $groups = Get-MgGroup -Filter "SecurityEnabled eq true and GroupTypes/any(c:c eq 'DynamicMembership')" -All -Property Id, DisplayName, Description, Mail, MembershipRule, MembershipRuleProcessingState, OnPremisesSyncEnabled, CreatedDateTime # 遍历获取每组所有者信息,组装导出数据 $exportData = foreach ($group in $groups) { # 获取组所有者 $owners = Get-MgGroupOwner -GroupId $group.Id -All # 处理所有者信息,多个所有者用分号分隔 $ownerNames = ($owners | ForEach-Object { $_.AdditionalProperties.displayName }) -join "; " $ownerUPNs = ($owners | ForEach-Object { $_.AdditionalProperties.userPrincipalName }) -join "; " # 构造导出对象 [PSCustomObject]@{ 组ID = $group.Id 组名称 = $group.DisplayName 组描述 = $group.Description 组邮箱 = $group.Mail 动态成员资格规则 = $group.MembershipRule 规则处理状态 = $group.MembershipRuleProcessingState 是否同步本地AD = $group.OnPremisesSyncEnabled 创建时间 = $group.CreatedDateTime 所有者名称 = $ownerNames 所有者用户主体名称 = $ownerUPNs } } # 导出到CSV $exportData | Export-Csv -Path $exportPath -Encoding UTF8 -NoTypeInformation
- 字段说明
- 动态成员资格规则:即动态组的配置规则内容
- 规则处理状态:显示当前规则为已启用/暂停等运行状态
- 所有者信息为空代表该组未配置所有者
- 注意事项
- 如果执行时提示没有权限,需要联系Azure AD管理员为你的账号开通对应Graph接口权限
- 导出路径如果设置为系统盘根目录时需要用管理员权限运行PowerShell,建议改到非系统盘路径
内容的提问来源于stack exchange,提问作者user15454588
相关产品推荐
相关产品推荐

