如何用PowerShell批量管理Office 365应用启用/禁用及适配组?
批量管理Office 365用户的应用启用/禁用(含Yammer批量配置)
我来帮你搞定批量操作的需求,不管是要批量禁用/启用所有用户的Office 365应用,还是把单个用户的Yammer禁用脚本改成批量执行,下面是具体的实现方案:
一、批量禁用/启用组织内所有用户的Office 365应用
Office 365的应用权限绑定在用户的License服务计划中,所以我们需要遍历用户的License,统一配置服务计划的启用/禁用状态。
1. 批量禁用所有用户的所有Office 365应用
这个脚本会遍历所有持有License的用户,将其License下的所有服务计划设为禁用:
# 获取租户内所有拥有License的用户 $allUsers = Get-MsolUser -All | Where-Object { $_.Licenses.Count -gt 0 } foreach ($user in $allUsers) { Write-Host "正在处理用户: $($user.UserPrincipalName)" foreach ($license in $user.Licenses) { # 获取当前License下的所有服务计划名称 $allServicePlans = $license.ServicePlan | Select-Object -ExpandProperty ServiceName # 创建License配置选项,禁用所有服务计划 $licenseOptions = New-MsolLicenseOptions -AccountSkuId $license.AccountSkuId -DisabledPlans $allServicePlans # 应用配置到用户 Set-MsolUserLicense -UserPrincipalName $user.UserPrincipalName -LicenseOptions $licenseOptions } }
2. 批量启用所有用户的所有Office 365应用
如果要恢复启用所有应用,只需将DisabledPlans设置为空数组即可:
$allUsers = Get-MsolUser -All | Where-Object { $_.Licenses.Count -gt 0 } foreach ($user in $allUsers) { Write-Host "正在处理用户: $($user.UserPrincipalName)" foreach ($license in $user.Licenses) { # 创建License配置选项,启用所有服务计划(空数组表示无禁用计划) $licenseOptions = New-MsolLicenseOptions -AccountSkuId $license.AccountSkuId -DisabledPlans @() Set-MsolUserLicense -UserPrincipalName $user.UserPrincipalName -LicenseOptions $licenseOptions } }
二、修改Yammer禁用脚本为批量执行
你提供的单个用户脚本逻辑很清晰,我们只需要把单个UPN的处理逻辑,替换为遍历目标用户集合即可。
1. 针对组织内所有用户禁用Yammer
遍历所有持有License的用户,保留原有禁用的服务计划,同时添加Yammer相关计划到禁用列表:
# 获取所有拥有License的用户 $allUsers = Get-MsolUser -All | Where-Object { $_.Licenses.Count -gt 0 } foreach ($user in $allUsers) { $UPN = $user.UserPrincipalName Write-Host "正在处理用户: $UPN" $LicenseDetails = $user.Licenses ForEach ($License in $LicenseDetails) { $DisabledOptions = @() # 保留已禁用的服务计划,同时加入所有Yammer相关计划 $License.ServiceStatus | ForEach { If ($_.ProvisioningStatus -eq "Disabled" -or $_.ServicePlan.ServiceName -like "*YAMMER*") { $DisabledOptions += "$($_.ServicePlan.ServiceName)" } } # 去重处理,避免重复添加同一服务计划导致报错 $DisabledOptions = $DisabledOptions | Select-Object -Unique $LicenseOptions = New-MsolLicenseOptions -AccountSkuId $License.AccountSkuId -DisabledPlans $DisabledOptions Set-MsolUserLicense -UserPrincipalName $UPN -LicenseOptions $LicenseOptions } }
2. 针对指定Outlook组的成员禁用Yammer
如果需要针对某Outlook组(通讯组/安全组)的成员执行,先获取组成员再批量处理:
# 替换为你的目标Outlook组名称或邮件地址 $groupName = "Your-Target-Group@domain.com" # 获取组内所有用户成员 $groupMembers = Get-MsolGroupMember -GroupObjectId (Get-MsolGroup -SearchString $groupName).ObjectId -All | Where-Object { $_.ObjectType -eq "User" } foreach ($member in $groupMembers) { $UPN = $member.EmailAddress Write-Host "正在处理组成员: $UPN" $user = Get-MsolUser -UserPrincipalName $UPN if ($user.Licenses.Count -eq 0) { Write-Host "用户 $UPN 无License,跳过..." continue } $LicenseDetails = $user.Licenses ForEach ($License in $LicenseDetails) { $DisabledOptions = @() $License.ServiceStatus | ForEach { If ($_.ProvisioningStatus -eq "Disabled" -or $_.ServicePlan.ServiceName -like "*YAMMER*") { $DisabledOptions += "$($_.ServicePlan.ServiceName)" } } $DisabledOptions = $DisabledOptions | Select-Object -Unique $LicenseOptions = New-MsolLicenseOptions -AccountSkuId $License.AccountSkuId -DisabledPlans $DisabledOptions Set-MsolUserLicense -UserPrincipalName $UPN -LicenseOptions $LicenseOptions } }
注意事项
- 执行脚本需要全局管理员或用户账户管理员权限,且需先安装
MSOnline模块(执行Install-Module MSOnline完成安装)。 - 建议先在单个测试用户或小范围用户中验证效果,再批量执行,避免影响全组织用户。
- 若租户用户数量较多,批量操作耗时较长,建议在非高峰时段执行。
内容的提问来源于stack exchange,提问作者Victor Arevalo
相关产品推荐
相关产品推荐

