AzureAD PowerShell模块无法分配应用扩展值,求Graph API解决方案
Hey there! I get that the AzureAD PowerShell module falls short when it comes to assigning extension values to objects, even though you can create/remove extension properties with Get/New/Remove-AzureADApplicationExtensionProperty. Let's walk through exactly how to do this using the Graph API, building on the work you've already done with Fiddler and Postman.
Step 1: Get the full extension property name
First, you need the exact, formatted name of your extension property—this is crucial because Graph API uses a specific naming convention.
Using PowerShell: Run the command you already know to list your app's extension properties:
Get-AzureADApplicationExtensionProperty -ObjectId "<your-application-object-id>"Look for the
Namefield in the output—it'll look likeextension_<app-id-without-hyphens>_<your-property-name>.Using Graph API: If you prefer, send a GET request to:
GET https://graph.microsoft.com/v1.0/applications/{your-app-id}/extensionPropertiesThe
namefield in the response is what you'll use in your update request.
Step 2: Secure a valid Bearer token
Since you've already tested this in Postman, you know the drill. You'll need an access token with the right permissions:
- For updating user extension values:
User.ReadWrite.All(orUser.ReadWriteif targeting a single user you own) - For other objects (groups, apps, etc.): Use the corresponding write permission (e.g.,
Group.ReadWrite.All)
Step 3: Send a PATCH request to assign/update the extension value
Graph API uses the PATCH method to update object properties, including extension values. Here's how to structure the request:
Example: Update a user's extension property
- Request URL:
PATCH https://graph.microsoft.com/v1.0/users/{user-id-or-user-principal-name} - Headers:
Authorization: Bearer <your-access-token>Content-Type: application/json
- Request Body (replace the extension name and value with yours):
{ "extension_abc123def456ghi789jkl012mno345pqr678_EmployeeID": "EMP-7890" }
For other object types
Just swap the endpoint to match the object you're updating:
- Groups:
PATCH https://graph.microsoft.com/v1.0/groups/{group-id} - Applications:
PATCH https://graph.microsoft.com/v1.0/applications/{app-id}
Step 4: Verify the change
To confirm the extension value was set correctly, send a GET request to fetch the object with your extension property included:
GET https://graph.microsoft.com/v1.0/users/{user-id}?$select=id,extension_abc123def456ghi789jkl012mno345pqr678_EmployeeID
Or back in PowerShell, you can check with:
Get-AzureADUser -ObjectId "<user-id>" | Select-Object -ExpandProperty ExtensionProperty
That's it! This should fill the gap left by the AzureAD PowerShell module for assigning those extension values.
内容的提问来源于stack exchange,提问作者Justin Dearing

