如何通过G Suite Admin SDK查询特定用户的已分配管理员角色?
1. How to Query a User's Assigned Prebuilt Admin Roles
To get the specific prebuilt admin roles assigned to a user, you need to use the admin.directory.rolemanagement.roleAssignments.list endpoint from the Admin SDK—this isn't available via the standard user details endpoint. Here's how to approach it:
- Endpoint Setup: Pass the
userKey(the user's primary email or unique ID) as a parameter to filter assignments for that specific user. You can also usemy_customeras thecustomerparameter if you're querying your own domain. - Map Role IDs: The response will return role assignment objects containing a
roleId. Cross-reference this ID with the role list you retrieved fromadmin.directory.rolemanagement.roles.listto match it to the corresponding prebuilt role name (like_GROUPS_ADMIN_ROLEor_HELP_DESK_ADMIN_ROLE).
Example response snippet from roleAssignments.list:
{ "kind": "admin#directory#roleAssignments", "etag": "\"BHP2ZsIq1HPrqEG_xY7Tkngn4lU/abc123\"", "items": [ { "kind": "admin#directory#roleAssignment", "etag": "\"BHP2ZsIq1HPrqEG_xY7Tkngn4lU/def456\"", "roleAssignmentId": "987654321", "roleId": "11870025812017153", "assignedTo": "xyz@demo.zxy.com", "scopeType": "CUSTOMER" } ] }
In this case, the roleId matches the _SEED_ADMIN_ROLE from your roles list, so the user has the Super Admin role.
2. Does isAdmin Become True for Any Admin Role?
No, the isAdmin field in the user details response only reflects whether the user has been assigned the Super Admin role (_SEED_ADMIN_ROLE).
For all other prebuilt admin roles (Groups Admin, User Management Admin, Help Desk Admin, Service Admin, Reseller Admin), the isAdmin field will stay false. Instead, you'll see the isDelegatedAdmin field set to true for users with any non-Super Admin admin roles.
Quick breakdown:
isAdmin: true→ User is a Super AdminisDelegatedAdmin: true→ User has one or more delegated admin roles (non-Super Admin)- Both
false→ User has no admin roles
内容的提问来源于stack exchange,提问作者TheCurious

