调用Get-MgRoleManagementDirectoryRoleEligibilityScheduleInstance遇模块加载错误求助
Get-MgRoleManagementDirectoryRoleEligibilityScheduleInstance加载失败问题 问题现象
调用Get-MgRoleManagementDirectoryRoleEligibilityScheduleInstance时触发错误:
The 'Get-MgRoleManagementDirectoryRoleEligibilityScheduleInstance' command was found in the module 'Microsoft.Graph.Identity.Governance', but the module could not be loaded due to the following error: [Could not load file or assembly 'Microsoft.Graph.Authentication, Version=2.19.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35'. Assembly with same name is already loaded]
当前已安装Microsoft Graph v2.29.1版本,且已卸载v2.19所有残留,但问题依旧存在。
解决方案
1. 彻底清理并重新安装Microsoft Graph模块
残留的模块文件或缓存会导致版本冲突,完全清理后重装可解决:
# 卸载所有Microsoft Graph模块 Get-InstalledModule Microsoft.Graph* | Uninstall-Module -Force -AllVersions # 删除模块文件残留 Remove-Item -Path "$env:ProgramFiles\WindowsPowerShell\Modules\Microsoft.Graph*" -Recurse -Force -ErrorAction SilentlyContinue Remove-Item -Path "$env:USERPROFILE\Documents\WindowsPowerShell\Modules\Microsoft.Graph*" -Recurse -Force -ErrorAction SilentlyContinue # 重装指定版本模块 Install-Module Microsoft.Graph -RequiredVersion 2.29.1 -Force -AllowClobber Install-Module Microsoft.Graph.Identity.Governance -RequiredVersion 2.29.1 -Force -AllowClobber
2. 在脚本开头强制导入指定版本模块
在脚本最顶部添加导入语句,避免加载旧版本模块:
# 强制导入v2.29.1版本的Microsoft Graph模块 Import-Module Microsoft.Graph -RequiredVersion 2.29.1 -Force Import-Module Microsoft.Graph.Identity.Governance -RequiredVersion 2.29.1 -Force
3. 清理当前PowerShell会话中的冲突模块
如果当前会话已加载旧版本模块,先卸载再重新导入:
# 查看已加载的Microsoft Graph模块 Get-Module Microsoft.Graph* # 卸载所有已加载的相关模块 Get-Module Microsoft.Graph* | Remove-Module -Force # 重新导入指定版本 Import-Module Microsoft.Graph -RequiredVersion 2.29.1 -Force Import-Module Microsoft.Graph.Identity.Governance -RequiredVersion 2.29.1 -Force
4. 统一认证方式,避免Az与Graph模块冲突
脚本中同时使用Connect-AzAccount和Connect-MgGraph可能引发认证模块冲突,可统一使用Microsoft Graph认证:
# 替换原Az认证逻辑,仅使用Graph认证 $mgContext = Get-MgContext if (-not $mgContext -or $mgContext.Scopes -notcontains "RoleManagementPolicy.ReadWrite.AzureADGroup", "Group.ReadWrite.All", "Directory.Read.All") { Connect-MgGraph -Scopes "RoleManagementPolicy.ReadWrite.AzureADGroup", "Group.ReadWrite.All", "Directory.Read.All" }
5. 清理全局程序集缓存(GAC)中的旧版本
如果上述方法无效,检查并清理GAC中的残留旧版本程序集:
# 查看GAC中的Microsoft.Graph.Authentication程序集 gacutil /l Microsoft.Graph.Authentication # 卸载指定版本的程序集 gacutil /u Microsoft.Graph.Authentication, Version=2.19.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
注:需以管理员身份运行,且需安装.NET Framework SDK才能使用gacutil工具
修改后的完整脚本
param ( [Parameter(Mandatory = $true)] [string]$GroupName, [Parameter(Mandatory = $true)] [string]$roleName ) # 强制导入指定版本的Microsoft Graph模块 Import-Module Microsoft.Graph -RequiredVersion 2.29.1 -Force Import-Module Microsoft.Graph.Identity.Governance -RequiredVersion 2.29.1 -Force try{ $mgContext = Get-MgContext if (-not $mgContext -or $mgContext.Scopes -notcontains "RoleManagementPolicy.ReadWrite.AzureADGroup", "Group.ReadWrite.All", "Directory.Read.All") { Connect-MgGraph -Scopes "RoleManagementPolicy.ReadWrite.AzureADGroup", "Group.ReadWrite.All", "Directory.Read.All" } } Catch{ Write-Host "Error retrieving Microsoft Graph context.. Attempting to login - $(Get-Date)" Connect-MgGraph -Scopes "RoleManagementPolicy.ReadWrite.AzureADGroup", "Group.ReadWrite.All", "Directory.Read.All" } try{ $ErrorActionPreference = "stop" $groupId = (Get-MgGroup -Filter "displayName eq '$GroupName'" -ErrorAction SilentlyContinue).Id If (!$groupId){ Write-Host "Error finding AAD Group : $GroupName - $(Get-Date)" Exit(1) } # 检查PIM角色分配(目录角色) $assignments = Get-MgRoleManagementDirectoryRoleEligibilityScheduleInstance -Filter "principalId eq '$groupId'" -All $activeAssignments = Get-MgRoleManagementDirectoryRoleAssignmentScheduleInstance -Filter "principalId eq '$groupId'" -All # 安全合并数组 $totalAssignments = @() + @($assignments) + @($activeAssignments) if ($totalAssignments.Count -eq 0) { Write-Host "No PIM role assignments found. Group will NOT be deleted." -ForegroundColor Yellow return } [array]$DirectoryRoles = Get-MgRoleManagementDirectoryRoleDefinition | Sort-Object DisplayName $roleDefinitionId = $DirectoryRoles | Where-Object {$_.DisplayName -eq $roleName} | Select-Object -ExpandProperty Id write-host "The role ID is $roleDefinitionId " $params = @{ action = "adminRemove" roleDefinitionId = $roleDefinitionId directoryScopeId = "/" principalId = $groupId } New-MgRoleManagementDirectoryRoleEligibilityScheduleRequest -BodyParameter $params # 等待删除操作同步 Start-Sleep -Seconds 3 # 删除组 Write-Host "Deleting group '$GroupName'..." -ForegroundColor Green Remove-MgGroup -GroupId $groupId -Confirm:$false Write-Host "Group and PIM assignments removed successfully." -ForegroundColor Green } Catch{ $err = $_.Exception.Message Write-Host "The error is as follows $err" -BackgroundColor Red }
内容的提问来源于stack exchange,提问作者learner

