You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用PowerShell无法设置Entra角色PIM通知告警邮箱求助

问题分析与解决方案

原代码失效的关键原因

当isDefaultRecipientsEnabled设为$true时,自定义的notificationRecipients会被API忽略,系统会优先使用默认收件人(如全局管理员组)。这是微软Graph API针对PIM通知规则的内置逻辑,也是你的代码无报错但不生效的核心原因。另外Beta版API本身存在行为不稳定的可能性,部分字段更新有隐藏限制。

可行的修复与替代方法

方法1:修正原API调用逻辑

将isDefaultRecipientsEnabled改为$false,让自定义邮箱生效,同时确保账号拥有Privileged Role Administrator或Global Administrator权限(无权限时API会静默失败)。修改后的代码:

$roleName = "Application Administrator"
$UserRoleId = (Get-MgRoleManagementDirectoryRoleDefinition | Where-Object { $_.DisplayName -eq $roleName }).Id
$policyID = (Get-MgPolicyRoleManagementPolicyAssignment -Filter "scopeId eq '/' and scopeType eq 'DirectoryRole' and roleDefinitionId eq '$UserRoleId'").PolicyId

$notificationRuleIds = @(
    "Notification_Admin_Admin_Eligibility", 
    "Notification_Admin_Admin_Assignment", 
    "Notification_Admin_EndUser_Assignment"
)

foreach ($ruleId in $notificationRuleIds) {
    $body = @{
        "@odata.type" = "#microsoft.graph.unifiedRoleManagementPolicyNotificationRule"
        "id" = $ruleId
        "notificationType" = "Email"
        "recipientType" = "Admin"
        "notificationLevel" = "All"
        "isDefaultRecipientsEnabled" = $false  # 关键修改:禁用默认收件人
        "notificationRecipients" = @("myemail@email.com")
    }

    Invoke-MgGraphRequest -Method PATCH `
        -Uri "https://graph.microsoft.com/beta/policies/roleManagementPolicies/$policyId/rules/$ruleId" `
        -Body ($body | ConvertTo-Json -Depth 10 -Compress) `
        -ContentType "application/json"
}

方法2:使用Graph PowerShell模块专用命令

直接使用模块的Update-MgPolicyRoleManagementPolicyRule命令,避免手动构造请求的潜在错误:

$roleName = "Application Administrator"
$UserRoleId = (Get-MgRoleManagementDirectoryRoleDefinition | Where-Object DisplayName -eq $roleName).Id
$policyAssignment = Get-MgPolicyRoleManagementPolicyAssignment -Filter "scopeId eq '/' and scopeType eq 'DirectoryRole' and roleDefinitionId eq '$UserRoleId'"
$policyID = $policyAssignment.PolicyId

$notificationRuleIds = @(
    "Notification_Admin_Admin_Eligibility", 
    "Notification_Admin_Admin_Assignment", 
    "Notification_Admin_EndUser_Assignment"
)

foreach ($ruleId in $notificationRuleIds) {
    $params = @{
        OdataType = "#microsoft.graph.unifiedRoleManagementPolicyNotificationRule"
        IsDefaultRecipientsEnabled = $false
        NotificationRecipients = @("myemail@email.com")
    }
    Update-MgPolicyRoleManagementPolicyRule -RoleManagementPolicyId $policyID -UnifiedRoleManagementPolicyRuleId $ruleId -BodyParameter $params
}

方法3:Entra管理中心手动设置

如果脚本方式暂时遇到阻碍,可以直接通过界面操作:

  • 登录Entra管理中心,进入身份治理 > 特权身份管理 > 角色 > Azure AD角色
  • 找到目标角色(如应用程序管理员),进入设置 > 通知
  • 修改对应通知项的收件人邮箱,保存即可

验证设置结果

修改后可通过以下命令确认配置是否生效:

Get-MgPolicyRoleManagementPolicyRule -RoleManagementPolicyId $policyID -UnifiedRoleManagementPolicyRuleId $ruleId | Select-Object IsDefaultRecipientsEnabled, NotificationRecipients

需确认IsDefaultRecipientsEnabled为False,且NotificationRecipients包含目标邮箱。

内容的提问来源于stack exchange,提问作者learner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 03:05:07