• Azure导出所有用户权限---powershell命令


     
    直接运行脚本
     
     
     
     
    #requires -Version 3.0 -Modules AzureRM.Resources
    param(
        [switch]
        $GroupRolesByUser
    )
    $ErrorActionPreference = 'Stop'

    Login-AzureRmAccount -ErrorVariable loginerror -Environment AzureChinaCloud
    If ($loginerror -ne $null)
    {
    Throw {"Error: An error occured during the login process, please correct the error and try again."}
    }
    Function Select-Subs
    {
        $ErrorActionPreference = 'SilentlyContinue'
        $Menu = 0
        $Subs = @(Get-AzureRmSubscription | select Name,ID,TenantId)
        Write-Host "Please select the subscription you want to use" -ForegroundColor Green;
        $Subs | %{Write-Host "[$($Menu)]" -ForegroundColor Cyan -NoNewline ;Write-host ". $($_.Name)";$Menu++;}
        $selection = Read-Host "Please select the Subscription Number - Valid numbers are 0 - $($Subs.count -1)"
        If ($Subs.item($selection) -ne $null)
        { Return @{name = $subs[$selection].Name;ID = $subs[$selection].ID} }
    }
    $SubscriptionSelection = Select-Subs
    Select-AzureRmSubscription -SubscriptionName $SubscriptionSelection.Name -ErrorAction Stop

    $ADUser = Get-AzureRmADUser
    function Resolve-AzureAdUsers {
    param(
            [string]$Displayname
        )
        ForEach($i in $ADUser){
            if( $i.displayName -eq $Displayname){return $i.UserPrincipalName}
           
        }
    }
    function Resolve-AzureAdGroupMembers
    {
        param(
            [guid]
            $GroupObjectId,
            $GroupList = (Get-AzureRmADGroup)
        )
       
        $VerbosePreference = 'continue'
        Write-Verbose -Message ('Resolving {0}' -f $GroupObjectId)
        $group = $GroupList | Where-Object -Property Id -EQ -Value $GroupObjectId
        $groupMembers = Get-AzureRmADGroupMember -GroupObjectId $GroupObjectId
        Write-Verbose -Message ('Found members {0}' -f ($groupMembers.DisplayName -join ', '))
        $parentGroup = @{
            Id          = $group.Id
            DisplayName = $group.DisplayName
            #UserPrincipalName = $group.UserPrincipalName
        }
        $groupMembers |
        Where-Object -Property Type -NE -Value Group |
        Select-Object -Property Id, DisplayName,UserPrincipalName, @{
            Name       = 'ParentGroup'
            Expression = { $parentGroup }
        }
        $groupMembers |
        Where-Object -Property type -EQ -Value Group |
        ForEach-Object -Process {
            Resolve-AzureAdGroupMembers -GroupObjectId $_.Id -GroupList $GroupList
        }
    }
    $roleAssignments = Get-AzureRmRoleAssignment -IncludeClassicAdministrators
    $members = $roleAssignments | ForEach-Object -Process {
        Write-Verbose -Message ('Processing Assignment {0}' -f $_.RoleDefinitionName)
        $roleAssignment = $_
       
        if($roleAssignment.ObjectType -eq 'Group')
        {
            Resolve-AzureAdGroupMembers -GroupObjectId $roleAssignment.ObjectId `
            | Select-Object -Property Id,
                SignInName,DisplayName,UserPrincipalName,
                ParentGroup, @{
                    Name       = 'RoleDefinitionName'
                    Expression = { $roleAssignment.RoleDefinitionName }
                }, @{
                    Name       = 'Scope'
                    Expression = { $roleAssignment.Scope }
                }, @{
                    Name       = 'CanDelegate'
                    Expression = { $roleAssignment.CanDelegate }
                }
        }
        else
        {
            $roleAssignment | Select-Object -Property @{
                    Name       = 'Id'
                    Expression = { $_.ObjectId }
                },
                SignInName, DisplayName,UserPrincipalName,
                @{
                    Name       = 'RoleDefinitionName'
                    Expression = { $roleAssignment.RoleDefinitionName }
                },
                Scope,
                CanDelegate
        }
    }
    if($GroupRolesByUser)
    {
        $members |
        Sort-Object -Property DisplayName, RoleDefinitionName `
        |
        Group-Object -Property DisplayName `
        |
        Select-Object -Property Count,
            Name,
            @{
                Name       = 'RoleDefinitions'
                Expression = { $_.Group.RoleDefinitionName -join ', ' }
            },
            ParentGroup
    }
    else
    {
        $members|Select-Object -Property Scope,Displayname,
        @{
                Name = 'LoginName'
                Expression = {$(Resolve-AzureAdUsers -Displayname $_.DisplayName)}
        },RoleDefinitionName|Out-GridView
    }
  • 相关阅读:
    防止跨域(jsonp详解)
    java-文件和I/O
    spring-AOP框架(基于AspectJ注解配置AOP)
    @RequestMapping、@Responsebody、@RequestBody和@PathVariable详解(转)
    spring-IOC容器(三)
    spring-IOC容器(二)
    spring-IOC容器(一)
    Spring4相关jar包介绍(转)
    Eclipse设置自动提示(转)
    java-环境安装及配置
  • 原文地址:https://www.cnblogs.com/lkun/p/10156042.html
Copyright © 2020-2023  润新知