关于在AAD、Intune、Entra中查找并删除主UPN已删除的孤立设备及从Autopilot移除的方法与PowerShell脚本请求
在Entra ID、Intune及Autopilot中查找并删除主UPN已删除的孤立设备的方法与PowerShell脚本
我之前刚好帮团队处理过一模一样的需求,下面就把实操步骤和验证过的PowerShell脚本分享给你,步骤清晰,脚本也加了详细注释,你可以跟着来:
一、前置准备
咱得先确保自己有足够的权限,比如全局管理员、Intune管理员或者云设备管理员角色,不然脚本执行的时候会报错。另外,需要安装最新版的Microsoft Graph PowerShell模块,打开PowerShell(以管理员身份运行),执行下面的命令安装:
Install-Module Microsoft.Graph -Force -AllowClobber
二、查找孤立设备的核心逻辑
孤立设备的关键特征是:设备的PrimaryUser(主用户)对应的UPN已经在Entra ID中被删除了。所以我们需要先获取所有设备,再逐个检查其主用户是否还存在,筛选出那些主用户不存在的设备。
三、完整PowerShell脚本(分阶段执行更安全)
我把脚本拆成了几个阶段,建议你先执行前几个阶段导出列表确认,没问题了再执行删除步骤,避免误删:
阶段1:连接Microsoft Graph并获取孤立设备列表
# 连接Microsoft Graph,需要的权限:Device.Read.All, User.Read.All, DeviceManagementManagedDevices.Read.All, DeviceServiceConfig.Read.All Connect-MgGraph -Scopes "Device.Read.All", "User.Read.All", "DeviceManagementManagedDevices.Read.All", "DeviceServiceConfig.Read.All", "DeviceManagementManagedDevices.ReadWrite.All", "DeviceServiceConfig.ReadWrite.All", "Device.ReadWrite.All" # 获取所有Entra ID中的设备 $allDevices = Get-MgDevice -All $true -Property Id, DisplayName, DeviceId, PrimaryUserId, AccountEnabled # 筛选出有主用户ID但对应的用户不存在的设备 $orphanedDevices = @() foreach ($device in $allDevices) { if ($device.PrimaryUserId) { try { $user = Get-MgUser -UserId $device.PrimaryUserId -ErrorAction Stop } catch { # 用户不存在,标记为孤立设备 $orphanedDevices += $device } } # 如果你还想包含没有主用户的设备,可以把下面的注释去掉 # else { # $orphanedDevices += $device # } } # 导出孤立设备列表到CSV,先手动核对确认 $orphanedDevices | Select-Object DisplayName, DeviceId, Id, PrimaryUserId | Export-Csv -Path "C:\Temp\OrphanedDevices.csv" -NoTypeInformation -Encoding UTF8 Write-Host "已导出孤立设备列表到C:\Temp\OrphanedDevices.csv,请先核对确认!" -ForegroundColor Cyan
阶段2:删除Intune中的孤立设备
确认列表没问题后,执行下面的脚本删除Intune中的对应设备:
# 获取所有Intune中的托管设备 $intuneDevices = Get-MgDeviceManagementManagedDevice -All $true -Property Id, DeviceName, AzureADDeviceId # 遍历孤立设备,删除Intune中的对应记录 foreach ($orphanedDevice in $orphanedDevices) { $intuneDevice = $intuneDevices | Where-Object { $_.AzureADDeviceId -eq $orphanedDevice.DeviceId } if ($intuneDevice) { try { Remove-MgDeviceManagementManagedDevice -ManagedDeviceId $intuneDevice.Id -ErrorAction Stop Write-Host "已成功删除Intune设备:$($orphanedDevice.DisplayName)" -ForegroundColor Green } catch { Write-Host "删除Intune设备$($orphanedDevice.DisplayName)失败:$($_.Exception.Message)" -ForegroundColor Red } } }
阶段3:从Autopilot中移除孤立设备
接下来处理Autopilot注册的设备:
# 获取所有Autopilot设备 $autopilotDevices = Get-MgDeviceServiceConfigDevice -All $true -Property Id, DeviceName, AzureADDeviceId # 遍历孤立设备,移除Autopilot记录 foreach ($orphanedDevice in $orphanedDevices) { $autopilotDevice = $autopilotDevices | Where-Object { $_.AzureADDeviceId -eq $orphanedDevice.DeviceId } if ($autopilotDevice) { try { Remove-MgDeviceServiceConfigDevice -DeviceId $autopilotDevice.Id -ErrorAction Stop Write-Host "已成功从Autopilot移除设备:$($orphanedDevice.DisplayName)" -ForegroundColor Green } catch { Write-Host "从Autopilot移除设备$($orphanedDevice.DisplayName)失败:$($_.Exception.Message)" -ForegroundColor Red } } }
阶段4:从Entra ID中删除孤立设备
最后清理Entra ID中的设备记录:
# 遍历孤立设备,删除Entra ID中的设备 foreach ($orphanedDevice in $orphanedDevices) { try { Remove-MgDevice -DeviceId $orphanedDevice.Id -ErrorAction Stop Write-Host "已成功删除Entra ID设备:$($orphanedDevice.DisplayName)" -ForegroundColor Green } catch { Write-Host "删除Entra ID设备$($orphanedDevice.DisplayName)失败:$($_.Exception.Message)" -ForegroundColor Red } }
四、重要注意事项
- 先核对,再删除:一定要先导出CSV列表手动检查,确认这些设备确实是没有主用户且不再使用的孤立设备,避免误删正常设备
- 权限问题:如果执行脚本时遇到权限错误,回到PowerShell重新连接Graph,确保请求的权限都被授予(连接时会弹出授权窗口,要全部允许)
- 无主用户的设备:脚本默认只筛选主用户存在但已删除的设备,如果要包含没有主用户的设备,把阶段1中对应的注释去掉即可
备注:内容来源于stack exchange,提问作者reinhardS
相关产品推荐
相关产品推荐

