【问题标题】:Is it possible to use Azure Graph API to change Notifications in PIM是否可以使用 Azure Graph API 更改 PIM 中的通知
【发布时间】:2020-10-06 20:56:57
【问题描述】:

我是 stackoverflow 的新手,所以如果您有任何反馈,请告诉我! 我创建了一个 powershell 脚本,通过使用 Microsoft (beta) Graph API for PIM 在 ResourceGroups 设置符合条件的角色分配。我使用invoke-restmethod来调用api:

$queryApiUri = "https://graph.microsoft.com/beta/privilegedAccess/azureResources/resources/$ResourceID/roleAssignments"
$Headers = @{}
$Headers.Add("Authorization","$($Token.token_type) "+ " " + "$($Token.access_token)")
$query = Invoke-RestMethod -Method Get -Uri $queryApiUri -Headers $Headers

这很好用,但是在激活角色时,所有作为通知发送的电子邮件都会让人们和管理员抓狂。在创建和激活时间以及需要批准者时发送通知。可以在门户中手动将通知设置为“仅限关键电子邮件”,以消除电子邮件泛滥。有人知道这是否可以通过使用 Graph API 来做到这一点?

【问题讨论】:

  • 嗨,你有机会看看我的回答吗?如果有任何进一步的问题,请告诉我。
  • 嗨,艾伦,是的,花了一段时间才弄清楚。但这绝对是有帮助的。如果我剥离 json 返回(浏览器上的 F12 ),我找到了我想要的东西。也有助于检查 ExpirationRule 设置等其他更改。非常感谢!!

标签: azure powershell graph roles pim


【解决方案1】:

当我们在门户修改'Critical emails only'并尝试get governanceRoleSetting时,我们会看到结果没有任何变化。

显然,Microsoft Graph 没有公开更新“仅限关键电子邮件”的方法。

但事实上,我们可以通过 Microsoft Graph 实现。在这里我将分享我的步骤。请注意,Microsoft Graph 文档中没有提到它。仅供参考。

以订阅所有者角色为例。

在浏览器中打开订阅所有者的编辑角色设置页面,按F12打开开发者工具。点击更新。然后我们将看到一个名为“roleSettingsv2”的请求。 (它不是 Microsoft Graph API)

查看响应,我们会在其中找到这样的“NotificationRule”。

{
    "ruleIdentifier": "NotificationRule",
    "setting": "{\"policies\":[{\"deliveryMechanism\":\"email\",\"setting\":[{\"customreceivers\":null,\"isdefaultreceiverenabled\":true,\"notificationlevel\":2,\"recipienttype\":2},{\"customreceivers\":null,\"isdefaultreceiverenabled\":true,\"notificationlevel\":2,\"recipienttype\":0},{\"customreceivers\":null,\"isdefaultreceiverenabled\":true,\"notificationlevel\":2,\"recipienttype\":1}]}]}"
}

Microsoft Graph API 中缺少它。

所以我们只需要在 Microsoft Graph 中使用 Update governanceRoleSetting 更新这个“NotificationRule”。

例如:

PATCH https://graph.microsoft.com/beta/privilegedAccess/azureResources/roleSettings/b12d879d-e521-4b0b-971c-7a2b6ac979ba

{
    "adminEligibleSettings": [{
            "ruleIdentifier": "ExpirationRule",
            "setting": "{\"permanentAssignment\":false,\"maximumGrantPeriodInMinutes\":525600}"
        }, {
            "ruleIdentifier": "MfaRule",
            "setting": "{\"mfaRequired\":false}"
        }, {
            "ruleIdentifier": "NotificationRule",
            "setting": "{\"policies\":[{\"deliveryMechanism\":\"email\",\"setting\":[{\"customreceivers\":null,\"isdefaultreceiverenabled\":true,\"notificationlevel\":2,\"recipienttype\":2},{\"customreceivers\":null,\"isdefaultreceiverenabled\":true,\"notificationlevel\":2,\"recipienttype\":0},{\"customreceivers\":null,\"isdefaultreceiverenabled\":true,\"notificationlevel\":2,\"recipienttype\":1}]}]}"
        }
    ]
}

您应该设置notificationlevel 的值。

请注意,\"notificationlevel\":2 将“仅重要电子邮件”设置为 False,\"notificationlevel\":1 设置为 True。

【讨论】:

  • 太棒了!您还可以添加 0/1/2 对应的收件人类型值吗?
  • 好的,我自己找到了丢失的细节以防有人需要它们:"caller":"Admin","operation":"ALL","level":"Eligible" -> 当成员被分配为合格时发送通知 "caller":"Admin","operation":"ALL","level":"Member" -> 当成员被分配时发送通知分配为活动 "caller":"EndUser","operation":"ALL","level":"Member" -> 当成员激活角色时结束通知; \"recipienttype\":2 -> 管理员 \"recipienttype\":0 -> 受让人 \"recipienttype\":1 ->审批人
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2022-08-23
  • 2022-01-22
  • 2019-04-07
  • 2011-05-21
相关资源
最近更新 更多