You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure无法获取目录角色的RoleDefinition,如何查询其定义与数据操作?

解决Azure目录角色RoleDefinition查询问题

你遇到的问题根源是Azure RBAC角色(如Reader)和Azure AD目录角色(如Privileged Role Administrator)属于不同的权限体系:前者通过Azure Management API管理,后者需使用Microsoft Graph API(或兼容旧版的Azure AD Graph API)查询。

正确查询目录角色的方法

方法1:使用Microsoft Graph API(推荐,最新版本)

查询所有目录角色定义:

az rest --method get --url 'https://graph.microsoft.com/v1.0/directoryRoleTemplates'

根据角色名称查询特定目录角色:

az rest --method get --url 'https://graph.microsoft.com/v1.0/directoryRoleTemplates?$filter=displayName eq "Privileged Role Administrator"'

根据角色ID查询详细信息(包含权限操作):

az rest --method get --url 'https://graph.microsoft.com/v1.0/directoryRoleTemplates/e8611ab8-c189-46e8-94e1-60213ab1f814'

方法2:使用Azure AD Graph API(兼容旧版场景)

若需适配旧有业务逻辑,可使用该API:

az rest --method get --url 'https://graph.windows.net/myorganization/directoryRoleTemplates/e8611ab8-c189-46e8-94e1-60213ab1f814?api-version=1.6'

关键说明

  • Azure Management API(management.azure.com)仅负责Azure资源的RBAC角色管理,无法访问Azure AD目录角色数据。
  • 执行上述API需具备对应权限:至少需Directory.Read.All或Directory.ReadWrite.All的Microsoft Graph权限(或Azure AD Graph的等效权限)。
  • 目录角色的权限操作会体现在返回结果的rolePermissions字段中,包含该角色允许的所有数据操作。

内容的提问来源于stack exchange,提问作者Daniel M.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 20:42:33