You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure PowerShell创建虚拟机时Security Type参数无效问题

Azure PowerShell 创建VM时securityType参数无效问题

我尝试使用以下Azure PowerShell代码创建名为VM1的虚拟机:

$groups = Get-AzResourceGroup -Name "vmTest" # Or any other resource group where I want to create the VM.
$rgName = $groups[0].ResourceGroupName
$rgId = "1234" # An arbitrary number that I set in case I need to create resources with a unique ID such as a Storage Account

# Create an Azure virtual machine (VM) named VM1 
$vmName = "VM1"
$securityTypeStnd = "Standard"
$osImage = "SQL Server 2017 on Windows Server 2019 - x64 Gen2"
$vmSize = "Standard_B2ms" # 2 vcpus, 8 GB RAM
$userName = "testuser"
$password = "Pa55w.rd1234"
$diskSKU = "Standard_LRS" # Standard HDD

$subnetName = "default"
$subnetAddress = "10.0.0.0/24" # Example subnet address
$vnetAddress = "10.0.0.0/16"
#$vnetName = "$vmName-vnet"
$vnetName= "VNet-$rgId"
$nsgName = "$vmName-nsg"
$nicName = "$vmName-nic"

# Creating the Network Security Group (NSG)
$nsgRuleRDP = New-AzNetworkSecurityRuleConfig -Name RDP  -Protocol Tcp  -Direction Inbound -Priority 1001 -SourceAddressPrefix * -SourcePortRange * -DestinationAddressPrefix * -DestinationPortRange 3389 -Access Allow
$nsg = New-AzNetworkSecurityGroup -ResourceGroupName $rgName -Location $groups[0].Location -Name $nsgName  -SecurityRules $nsgRuleRDP

# Create the Subnet with the previously created NSG attached
$defaultSubnet = New-AzVirtualNetworkSubnetConfig -Name $subnetName -AddressPrefix $subnetAddress -NetworkSecurityGroup $nsg
# Create the virtual network with the specified address space and subnet
$vnet = New-AzVirtualNetwork -Name $vnetName -ResourceGroupName $rgName -Location $groups[0].Location -AddressPrefix $vnetAddress -Subnet $defaultSubnet
# Create the Network Interface Card (NIC) for the VM
#$nic = New-AzNetworkInterface -Name $nicName -ResourceGroupName $rgName -Location $groups[0].Location -SubnetId $vnet.Subnets[0].Id -NetworkSecurityGroupId $nsg.Id #-EnableAcceleratedNetworking

# Credentials for Local Admin account
$VMLocalAdminSecurePassword = ConvertTo-SecureString -String $password -AsPlainText -Force
$credential = New-Object System.Management.Automation.PSCredential ($userName, $VMLocalAdminSecurePassword)


# Disk setup
# https://learn.microsoft.com/en-us/powershell/module/az.compute/new-azdiskconfig?view=azps-14.0.0
# -SkuName
#   Specifies the Sku name of the storage account. Available values are Standard_LRS, Premium_LRS, StandardSSD_LRS, and UltraSSD_LRS, Premium_ZRS and StandardSSD_ZRS. UltraSSD_LRS can only be used with Empty value for CreateOption parameter.
$diskconfig = New-AzDiskConfig -Location $groups[0].Location -DiskSizeGB 127 -SkuName $diskSKU -OsType Windows -CreateOption Empty # I must specify the create option as Empty for a new disk, otherwise I'll get an error.
New-AzDisk -ResourceGroupName $rgName -DiskName 'Disk01' -Disk $diskconfig
$disk = Get-AzDisk -ResourceGroupName $rgName -DiskName 'Disk01'


# Step 1: Create the public IP
$publicIp = New-AzPublicIpAddress -Name "$vmName-pip" `
    -ResourceGroupName $rgName `
    -Location $groups[0].Location `
    -AllocationMethod Static `
    -Sku Basic

# Step 2: Create the NIC and attach the public IP
$subnet = Get-AzVirtualNetworkSubnetConfig -Name $subnetName -VirtualNetwork $vnet
$nic = New-AzNetworkInterface -Name "$vmName-NIC" `
    -ResourceGroupName $rgName `
    -Location $groups[0].Location `
    -SubnetId $subnet.Id `
    -PublicIpAddressId $publicIp.Id

# Step 3: Create the VM config and attach the NIC
# To check SKUs available for the image, use:
# Get-AzVMImageSku -Location $groups[0].location -PublisherName "MicrosoftWindowsServer" -Offer "WindowsServer" | Where-Object { $_.Skus -like "2019*" } | Select Skus
# For the selected image Trusted Launch is not supported, so I will use Standard security type.
$vmConfig = New-AzVMConfig -VMName $vmName -VMSize $vmSize `
    | Set-AzVMOperatingSystem -Windows -ComputerName $vmName -Credential $credential `
    | Set-AzVMSourceImage -PublisherName "MicrosoftWindowsServer" `
        -Offer "WindowsServer" -Skus "2019-Datacenter" -Version "latest" `
    | Add-AzVMNetworkInterface -Id $nic.Id `
    | Set-AzVMBootDiagnostic -Disable `
    | Set-AzVMSecurityProfile -SecurityType $securityTypeStnd

$VMConfig = Set-AzVMSecurityProfile -VM $VMConfig -SecurityType Standard

# Step 4: Create the VM
New-AzVM -ResourceGroupName $rgName -Location $groups[0].Location -VM $vmConfig

执行时收到如下错误:

PS /Users/alvaro> $vmConfig = New-AzVMConfig -VMName $vmName -VMSize $vmSize `
>>     | Set-AzVMOperatingSystem -Windows -ComputerName $vmName -Credential $credential `
>>     | Set-AzVMSourceImage -PublisherName "MicrosoftWindowsServer" `
>>         -Offer "WindowsServer" -Skus "2019-Datacenter" -Version "latest" `
>>     | Add-AzVMNetworkInterface -Id $nic.Id `
>>     | Set-AzVMBootDiagnostic -Disable
PS /Users/alvaro> New-AzVM -ResourceGroupName $rgName -Location $groups[0].Location -VM $vmConfig
Consider upgrading security for your workloads using Azure Trusted Launch VMs. To know more about Trusted Launch, please visit https://aka.ms/TrustedLaunch
New-AzVM: The value of parameter securityProfile.securityType is invalid.
ErrorCode: InvalidParameter
ErrorMessage: The value of parameter securityProfile.securityType is invalid.
ErrorTarget: securityProfile.securityType
StatusCode: 400
ReasonPhrase: 
OperationID : aee78f00-aa98-485b-9617-82f1416e5601

错误由$VMConfig = Set-AzVMSecurityProfile -VM $VMConfig -SecurityType Standard这一行触发,我已参考Set-AzVMSecurityProfile官方文档,多次尝试仍无法解决该问题。


问题原因及解决办法

  • 核心原因:重复调用Set-AzVMSecurityProfile设置SecurityType导致参数冲突;同时Windows Server 2019镜像默认安全类型就是Standard,无需手动指定,部分Azure PowerShell版本中显式设置该值会被API判定为无效。
  • 解决步骤:
    1. 删除重复的安全设置代码:直接移除$VMConfig = Set-AzVMSecurityProfile -VM $VMConfig -SecurityType Standard这一行,管道中已经设置过一次安全类型,重复操作会引发错误。
    2. 可选:省略手动安全类型设置:如果没有特殊安全需求,完全可以去掉管道中的| Set-AzVMSecurityProfile -SecurityType $securityTypeStnd,让VM使用默认配置,避免兼容性问题。
    3. 升级Azure PowerShell模块:确保模块为最新版本,旧版本可能存在参数值兼容问题,执行Update-Module -Name Az完成升级。

修改后的关键代码片段

# Step 3: Create the VM config and attach the NIC
$vmConfig = New-AzVMConfig -VMName $vmName -VMSize $vmSize `
    | Set-AzVMOperatingSystem -Windows -ComputerName $vmName -Credential $credential `
    | Set-AzVMSourceImage -PublisherName "MicrosoftWindowsServer" `
        -Offer "WindowsServer" -Skus "2019-Datacenter" -Version "latest" `
    | Add-AzVMNetworkInterface -Id $nic.Id `
    | Set-AzVMBootDiagnostic -Disable
# 无需额外设置SecurityType,默认即为Standard

内容的提问来源于stack exchange,提问作者Álvaro

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 01:12:06