Azure PowerShell创建虚拟机时Security Type参数无效问题
Azure PowerShell 创建VM时securityType参数无效问题
我尝试使用以下Azure PowerShell代码创建名为VM1的虚拟机:
$groups = Get-AzResourceGroup -Name "vmTest" # Or any other resource group where I want to create the VM. $rgName = $groups[0].ResourceGroupName $rgId = "1234" # An arbitrary number that I set in case I need to create resources with a unique ID such as a Storage Account # Create an Azure virtual machine (VM) named VM1 $vmName = "VM1" $securityTypeStnd = "Standard" $osImage = "SQL Server 2017 on Windows Server 2019 - x64 Gen2" $vmSize = "Standard_B2ms" # 2 vcpus, 8 GB RAM $userName = "testuser" $password = "Pa55w.rd1234" $diskSKU = "Standard_LRS" # Standard HDD $subnetName = "default" $subnetAddress = "10.0.0.0/24" # Example subnet address $vnetAddress = "10.0.0.0/16" #$vnetName = "$vmName-vnet" $vnetName= "VNet-$rgId" $nsgName = "$vmName-nsg" $nicName = "$vmName-nic" # Creating the Network Security Group (NSG) $nsgRuleRDP = New-AzNetworkSecurityRuleConfig -Name RDP -Protocol Tcp -Direction Inbound -Priority 1001 -SourceAddressPrefix * -SourcePortRange * -DestinationAddressPrefix * -DestinationPortRange 3389 -Access Allow $nsg = New-AzNetworkSecurityGroup -ResourceGroupName $rgName -Location $groups[0].Location -Name $nsgName -SecurityRules $nsgRuleRDP # Create the Subnet with the previously created NSG attached $defaultSubnet = New-AzVirtualNetworkSubnetConfig -Name $subnetName -AddressPrefix $subnetAddress -NetworkSecurityGroup $nsg # Create the virtual network with the specified address space and subnet $vnet = New-AzVirtualNetwork -Name $vnetName -ResourceGroupName $rgName -Location $groups[0].Location -AddressPrefix $vnetAddress -Subnet $defaultSubnet # Create the Network Interface Card (NIC) for the VM #$nic = New-AzNetworkInterface -Name $nicName -ResourceGroupName $rgName -Location $groups[0].Location -SubnetId $vnet.Subnets[0].Id -NetworkSecurityGroupId $nsg.Id #-EnableAcceleratedNetworking # Credentials for Local Admin account $VMLocalAdminSecurePassword = ConvertTo-SecureString -String $password -AsPlainText -Force $credential = New-Object System.Management.Automation.PSCredential ($userName, $VMLocalAdminSecurePassword) # Disk setup # https://learn.microsoft.com/en-us/powershell/module/az.compute/new-azdiskconfig?view=azps-14.0.0 # -SkuName # Specifies the Sku name of the storage account. Available values are Standard_LRS, Premium_LRS, StandardSSD_LRS, and UltraSSD_LRS, Premium_ZRS and StandardSSD_ZRS. UltraSSD_LRS can only be used with Empty value for CreateOption parameter. $diskconfig = New-AzDiskConfig -Location $groups[0].Location -DiskSizeGB 127 -SkuName $diskSKU -OsType Windows -CreateOption Empty # I must specify the create option as Empty for a new disk, otherwise I'll get an error. New-AzDisk -ResourceGroupName $rgName -DiskName 'Disk01' -Disk $diskconfig $disk = Get-AzDisk -ResourceGroupName $rgName -DiskName 'Disk01' # Step 1: Create the public IP $publicIp = New-AzPublicIpAddress -Name "$vmName-pip" ` -ResourceGroupName $rgName ` -Location $groups[0].Location ` -AllocationMethod Static ` -Sku Basic # Step 2: Create the NIC and attach the public IP $subnet = Get-AzVirtualNetworkSubnetConfig -Name $subnetName -VirtualNetwork $vnet $nic = New-AzNetworkInterface -Name "$vmName-NIC" ` -ResourceGroupName $rgName ` -Location $groups[0].Location ` -SubnetId $subnet.Id ` -PublicIpAddressId $publicIp.Id # Step 3: Create the VM config and attach the NIC # To check SKUs available for the image, use: # Get-AzVMImageSku -Location $groups[0].location -PublisherName "MicrosoftWindowsServer" -Offer "WindowsServer" | Where-Object { $_.Skus -like "2019*" } | Select Skus # For the selected image Trusted Launch is not supported, so I will use Standard security type. $vmConfig = New-AzVMConfig -VMName $vmName -VMSize $vmSize ` | Set-AzVMOperatingSystem -Windows -ComputerName $vmName -Credential $credential ` | Set-AzVMSourceImage -PublisherName "MicrosoftWindowsServer" ` -Offer "WindowsServer" -Skus "2019-Datacenter" -Version "latest" ` | Add-AzVMNetworkInterface -Id $nic.Id ` | Set-AzVMBootDiagnostic -Disable ` | Set-AzVMSecurityProfile -SecurityType $securityTypeStnd $VMConfig = Set-AzVMSecurityProfile -VM $VMConfig -SecurityType Standard # Step 4: Create the VM New-AzVM -ResourceGroupName $rgName -Location $groups[0].Location -VM $vmConfig
执行时收到如下错误:
PS /Users/alvaro> $vmConfig = New-AzVMConfig -VMName $vmName -VMSize $vmSize ` >> | Set-AzVMOperatingSystem -Windows -ComputerName $vmName -Credential $credential ` >> | Set-AzVMSourceImage -PublisherName "MicrosoftWindowsServer" ` >> -Offer "WindowsServer" -Skus "2019-Datacenter" -Version "latest" ` >> | Add-AzVMNetworkInterface -Id $nic.Id ` >> | Set-AzVMBootDiagnostic -Disable PS /Users/alvaro> New-AzVM -ResourceGroupName $rgName -Location $groups[0].Location -VM $vmConfig Consider upgrading security for your workloads using Azure Trusted Launch VMs. To know more about Trusted Launch, please visit https://aka.ms/TrustedLaunch New-AzVM: The value of parameter securityProfile.securityType is invalid. ErrorCode: InvalidParameter ErrorMessage: The value of parameter securityProfile.securityType is invalid. ErrorTarget: securityProfile.securityType StatusCode: 400 ReasonPhrase: OperationID : aee78f00-aa98-485b-9617-82f1416e5601
错误由$VMConfig = Set-AzVMSecurityProfile -VM $VMConfig -SecurityType Standard这一行触发,我已参考Set-AzVMSecurityProfile官方文档,多次尝试仍无法解决该问题。
问题原因及解决办法
- 核心原因:重复调用
Set-AzVMSecurityProfile设置SecurityType导致参数冲突;同时Windows Server 2019镜像默认安全类型就是Standard,无需手动指定,部分Azure PowerShell版本中显式设置该值会被API判定为无效。 - 解决步骤:
- 删除重复的安全设置代码:直接移除
$VMConfig = Set-AzVMSecurityProfile -VM $VMConfig -SecurityType Standard这一行,管道中已经设置过一次安全类型,重复操作会引发错误。 - 可选:省略手动安全类型设置:如果没有特殊安全需求,完全可以去掉管道中的
| Set-AzVMSecurityProfile -SecurityType $securityTypeStnd,让VM使用默认配置,避免兼容性问题。 - 升级Azure PowerShell模块:确保模块为最新版本,旧版本可能存在参数值兼容问题,执行
Update-Module -Name Az完成升级。
- 删除重复的安全设置代码:直接移除
修改后的关键代码片段
# Step 3: Create the VM config and attach the NIC $vmConfig = New-AzVMConfig -VMName $vmName -VMSize $vmSize ` | Set-AzVMOperatingSystem -Windows -ComputerName $vmName -Credential $credential ` | Set-AzVMSourceImage -PublisherName "MicrosoftWindowsServer" ` -Offer "WindowsServer" -Skus "2019-Datacenter" -Version "latest" ` | Add-AzVMNetworkInterface -Id $nic.Id ` | Set-AzVMBootDiagnostic -Disable # 无需额外设置SecurityType,默认即为Standard
内容的提问来源于stack exchange,提问作者Álvaro
相关产品推荐
相关产品推荐

