Azure AD用户数据获取问题:Graph API无法返回特定属性
我之前也踩过这个坑!你提到的LastPasswordChangeTimestamp、StrongAuthenticationRequirements、StrongPasswordRequired、PasswordNeverExpires这几个属性,确实没法通过Microsoft Graph API或者旧版AD Graph API直接获取——它们属于Azure AD的MSOL(Microsoft Online)专属遗留属性,并没有暴露在Graph的用户实体接口里,所以只能通过Msol PowerShell模块来获取。
下面是具体的操作步骤和细节:
1. 准备Msol PowerShell模块
如果还没安装过,先执行以下命令安装模块(需要管理员权限):
Install-Module MSOnline -Force
2. 连接到Azure AD服务
使用Connect-MsolService完成登录,这里有几种常用的登录方式:
- 交互式登录:直接执行命令,会弹出登录窗口让你输入账号密码:
Connect-MsolService - 使用本地凭据对象:适合脚本自动化场景,提前获取凭据再登录:
$cred = Get-Credential Connect-MsolService -Credential $cred - 服务主体登录:如果是无人值守的自动化任务,可以用应用程序身份登录(需要给服务主体分配
Directory Readers之类的权限):$tenantId = "你的租户ID" $clientId = "应用程序ID" $clientSecret = ConvertTo-SecureString "应用程序密钥" -AsPlainText -Force $cred = New-Object System.Management.Automation.PSCredential($clientId, $clientSecret) Connect-MsolService -Credential $cred -TenantId $tenantId
3. 获取目标属性
登录成功后,就可以用Get-MsolUser提取你需要的属性了:
获取所有用户的目标属性
Get-MsolUser -All | Select-Object UserPrincipalName, LastPasswordChangeTimestamp, StrongAuthenticationRequirements, StrongPasswordRequired, PasswordNeverExpires
获取单个用户的目标属性
Get-MsolUser -UserPrincipalName "user@yourdomain.com" | Select-Object UserPrincipalName, LastPasswordChangeTimestamp, StrongAuthenticationRequirements, StrongPasswordRequired, PasswordNeverExpires
额外提示
- 关于
StrongAuthenticationRequirements:这个属性是一个集合对象,里面包含MFA的具体配置(比如是否强制启用、适用范围等),如果想直观查看MFA状态,可以自定义输出:Get-MsolUser -All | Select-Object UserPrincipalName, @{Name='MFAStatus'; Expression={$_.StrongAuthenticationRequirements.State}} - 如果你需要批量导出这些数据到CSV,可以追加导出命令:
Get-MsolUser -All | Select-Object UserPrincipalName, LastPasswordChangeTimestamp, StrongPasswordRequired, PasswordNeverExpires, @{Name='MFAStatus'; Expression={$_.StrongAuthenticationRequirements.State}} | Export-Csv -Path "AzureADUserProperties.csv" -NoTypeInformation
内容的提问来源于stack exchange,提问作者Elrom Behar
相关产品推荐
相关产品推荐

