如何通过PowerShell脚本获取指定用户关联的Azure订阅列表?
PowerShell Script to Get Azure Subscriptions for a Specific User
Hey there, I’ve put together a practical PowerShell script that handles Azure authentication and retrieves subscriptions associated with a specified user. Here’s everything you need:
The Complete Script
# Prompt for the target user's User Principal Name (UPN) $targetUser = Read-Host "Enter the UPN of the user you want to check (e.g., user@domain.com)" # Check if AzureRM module is installed; install if missing if (-not (Get-Module -Name AzureRM -ListAvailable)) { Write-Warning "AzureRM module not detected. Installing it now..." Install-Module -Name AzureRM -AllowClobber -Scope CurrentUser -Force } Import-Module AzureRM -Force # Handle Azure login (reuse existing session if available) try { $currentContext = Get-AzureRmContext if (-not $currentContext.Account) { Write-Host "Please log in to your Azure account..." Connect-AzureRmAccount } } catch { Write-Error "Authentication failed: $_" exit 1 } # Get all subscriptions accessible to the logged-in account $allSubscriptions = Get-AzureRmSubscription # Filter subscriptions where the target user has role assignments $userAssociatedSubscriptions = @() foreach ($subscription in $allSubscriptions) { # Switch context to the current subscription Set-AzureRmContext -Subscription $subscription.Id | Out-Null # Fetch role assignments for the target user $userRoles = Get-AzureRmRoleAssignment -SignInName $targetUser -ErrorAction SilentlyContinue if ($userRoles) { $userAssociatedSubscriptions += [PSCustomObject]@{ SubscriptionName = $subscription.Name SubscriptionID = $subscription.Id TenantID = $subscription.TenantId AssignedRoles = $userRoles.RoleDefinitionName -join ", " } } } # Display results if ($userAssociatedSubscriptions.Count -gt 0) { Write-Host "`nSubscriptions linked to $targetUser :" $userAssociatedSubscriptions | Format-Table -AutoSize } else { Write-Host "`nNo subscriptions found for user $targetUser." }
How This Works
- Module Management: The script checks if the AzureRM module is installed and installs it automatically (you may need admin rights for the install, or adjust the
-Scopeparameter if needed). - Smart Authentication: It checks if you’re already logged into Azure; if not, it prompts you to sign in with your credentials.
- Targeted Filtering: It loops through all subscriptions your logged-in account can access, then checks for role assignments tied to the specified user. Only subscriptions where the user has at least one role are included in the output.
- Clear Output: Returns a formatted table with key details like subscription name, ID, tenant ID, and the roles the user holds on each subscription.
Important Considerations
- Permissions: Your logged-in account needs sufficient access (like Reader or RBAC Administrator) to view role assignments across the subscriptions you’re checking.
- Tenant Limits: This script works within the tenant you authenticate to. If you need to check subscriptions across multiple tenants, you’d need to add logic to loop through different tenant contexts.
- Az Module Note: AzureRM is a legacy module. If you’re using the newer Az module, replace all
AzureRMcmdlets with theirAzequivalents (e.g.,Connect-AzAccount,Get-AzSubscription).
内容的提问来源于stack exchange,提问作者in.sane.prasain
相关产品推荐
相关产品推荐

