如何使用 Microsoft Graph PowerShell 检索管理单元的属性和关系

检索管理单元(AU)的属性和关系可提供其结构和功能的关键见解。Microsoft Graph PowerShell 通过 Get-MgDirectoryAdministrativeUnit cmdlet 帮助您完成此操作。通过了解 AU 的连接,管理员可以有效地委派职责并执行安全策略。

使用 Microsoft Graph PowerShell 检索 AU 的属性

前提条件

在使用 Get-MgDirectoryAdministrativeUnit cmdlet 之前,请确保以下事项:

  • If the Microsoft Graph PowerShell module is not installed, install using this script:
    Install-Module Microsoft.Graph -Scope CurrentUser
  • Connect to Microsoft Graph PowerShell with the following permission retrieve an AU's relationship and its properties:
    AdministrativeUnit.Read.All

使用 Get-MgDirectoryAdministrativeUnit cmdlet

在 Microsoft Graph PowerShell 中运行以下命令以检索 AU 的关系及其属性:

Get-MgDirectoryAdministrativeUnit
[-ExpandProperty <String[]>]
[-Property <String[]>]
[-Filter <String>]
[-Search <String>]
[-Skip <Int32>]
[-Sort <String[]>]
[-Top <Int32>]
[-ResponseHeadersVariable <String>]
[-Headers <IDictionary>]
[-PageSize <Int32>]
[-All]
[-CountVariable <String>]
[-ProgressAction <ActionPreference>]
[<CommonParameters>]

支持的参数

下表包含可与 Get-MgDirectoryAdministrativeUnit cmdlet 一起使用的一些参数。

参数 描述
-All 列出所有页面。
-CountVariable 指定集合中项目的总数。
-ExpandProperty 展开相关实体。
-Filter 按属性值筛选项目。
-Headers 提供将添加到请求中的可选标头。

使用 Microsoft Graph PowerShell 检索 AU 属性的限制

  • PowerShell 脚本在不同用例和场景下可能变得复杂。
  • IT 管理员可能需要花费大量时间调试错误,进而影响生产力。
  • 委派可能变得复杂,因为技术人员需要提升权限。

ADManager Plus亮点

告别复杂的 PowerShell 脚本,使用 ADManager Plus —— 一款身份治理和管理解决方案。ADManager Plus 的全面 Microsoft Entra ID 管理和报告 简化了从单一用户友好控制台执行的复杂管理任务:

  • 管理用户、联系人、组、许可证及其他 Microsoft Entra ID 对象,无需脚本,集中控制。
  • 通过 自动化 和协调跨多个平台的用户配置、取消配置及许可证分配等任务,减少人为错误。
  • Delegate tasks 给技术人员,无需提升其本地权限。
  • 利用超过 200 个预置报告,密切监控您的 IT 环境。
  • 通过智能工作流监控委派活动。
  • 通过 AD、Microsoft Entra ID 和 Google Workspace 备份与恢复,确保业务连续性。

使用 ADManager Plus 实现无脚本的 Microsoft Entra ID 管理和报告

 
  • 使用 Microsoft Graph PowerShell 检索 AU 的属性
  • 使用 Microsoft Graph PowerShell 检索 AU 属性的限制
  • ADManager Plus亮点
Active Directory管理与报告的一站式解决方案
电子邮件下载链接 Email the ADManager Plus download link