Get-MgGroup命令近期是否有变更?PowerShell脚本突发故障求助
Azure DevOps PowerShell脚本突然失效排查
问题背景
我有一个在Azure DevOps的PowerShell@5任务中运行的PowerShell脚本,此前正常运行一两年,但最近突然失效。脚本通过**基于密钥的Azure资源管理器服务连接(非联邦认证)**向Azure认证,服务连接拥有订阅级别权限。
关联服务主体配置
关联的服务主体(应用注册)拥有订阅Owner角色,还配置了第二个密码密钥用于az login命令。其API权限如下:
Application.ReadWrite.All Directory.ReadWrite.All Group.create Group.ReadWrite.All GroupMember.ReadWrite.All RoleManagement.ReadWrite.Directory User.ReadWrite.All
脚本执行代码
# Login to Azure and DevOps az login --service-principal -u \"$azureSPAppId\" -p \"$azureSPPwd\" --tenant \"$tenantId\" --allow-no-subscriptions az --version az account set --subscription $subId az group create --name $resourceGroup --location $location Write-Output \"exec: Update azure\" az upgrade # The service principal for the pipeline requests the token Write-Output \"exec: Get accessToken\" # $secureToken = (Get-AzAccessToken -Resource \"https://graph.microsoft.com\").Token | ConvertTo-SecureString -AsPlainText # Connect-MgGraph -AccessToken $secureToken $allAccess = (Get-AzAccessToken -ResourceTypeName MSGraph) $token = (Get-AzAccessToken -ResourceTypeName MSGraph).token $secureToken = ConvertTo-SecureString $token -AsPlainText -Force Connect-MgGraph -AccessToken $secureToken Write-Output \"exec: Get service principal's permissions\" Get-MgContext Write-Output \"exec: Get-MgGroup if it exists?\" $directoryReadersGroupId = (Get-MgGroup -Filter \"DisplayName eq '$directoryReadersGroupName'\").Id
错误现象
Get-MgContext返回结果正常,但执行Get-MgGroup时出现错误:
IDX14102: Unable to decode the header '[PII of type
我是PowerShell新手,已搜索同错误线程并调整Connect-MgGraph语法,问题仍存在。补充信息:az登录截图、$allAccess/$token/$secureToken输出截图已提供。
疑问
近期是否有变更导致脚本失效?是否存在已知中断性变更?
内容的提问来源于stack exchange,提问作者Aiden Dipple
相关产品推荐
相关产品推荐

