【问题标题】:Microsoft Graph API - Get group owner details along with group details in azureMicrosoft Graph API - 获取组所有者详细信息以及 azure 中的组详细信息
【发布时间】:2019-02-12 04:13:15
【问题描述】:

在 Azure 中,我可以找到一个用于获取组详细信息的 API,如下所示

https://graph.microsoft.com/v1.0/groups

这将为我提供如下所示的所有组详细信息

{  
  "value": [  
    {  
      "id": "/groups/53c765632095310385020001",  
      "name": "Administrators",  
      "description": "Administrators is a built-in group. Its membership is managed by the system. Microsoft Azure subscription administrators fall into this group.",  
      "builtIn": true,  
      "type": "system",  
      "externalId": null  
    },  
    {  
      "id": "/groups/53c765632095310385020002",  
      "name": "Developers",  
      "description": "Developers is a built-in group. Its membership is managed by the system. Signed-in users fall into this group.",  
      "builtIn": true,  
      "type": "system",  
      "externalId": null  
    },  
    {  
      "id": "/groups/53c765632095310385020003",  
      "name": "Guests",  
      "description": "Guests is a built-in group. Its membership is managed by the system. Unauthenticated users visiting the developer portal fall into this group.",  
      "builtIn": true,  
      "type": "system",  
      "externalId": null  
    }  
  ],  
  "count": 3,  
  "nextLink": null  
}  

但问题是我还需要组所有者详细信息以及组详细信息。目前我调用另一个 API 如下所示来获取组所有者详细信息

https://graph.microsoft.com/v1.0/groups/{groupId}/owners

是否有任何 API 或任何其他方式可以让我在 azure 中一次性获取组所有者详细信息以及组详细信息

【问题讨论】:

    标签: rest azure azure-active-directory microsoft-graph-api azure-resource-group


    【解决方案1】:

    Microsoft Graph API 支持一些可选的查询参数,例如选择、过滤、展开、搜索等,这有助于控制您在响应查询时返回的数据。你可以阅读他们here

    expand parameter 可能对您的用例有所帮助。

    我很快从Microsoft Graph Explorer 尝试了如下查询,它返回了组信息以及每个组的所有者集合。

    https://graph.microsoft.com/v1.0/groups?$expand=owners
    

    免责声明:Microsoft Docs for expand 参数有一个注释,上面写着类似

    使用派生自 directoryObject 的 Azure AD 资源,例如用户 和组, $expand 仅支持 beta 并且通常返回一个 扩展关系最多 20 项。

    虽然,上面提到的使用 v1.0 的查询至少从 Graph explorer 对我来说确实可以正常工作。因此,在开始依赖它之前,请尽可能多地进行测试(也包括大量的组)。如果我找到更多关于相同的最新文档,我也会更新。

    这是我在上面提到的查询中得到的确切回复。它很大,我只包括了 2 个组并删除了其他组,以便您了解。

    重要的是要注意所有者集合与组一起存在。请注意,第一个组没有分配所有者,但第二个组有 2 个用户作为所有者。

    请求

    GET https://graph.microsoft.com/v1.0/groups?$expand=owners
    

    回复

    {
        "@odata.context": "https://graph.microsoft.com/v1.0/$metadata#groups",
        "value": [
            {
                "id": "xxxx-redacted-49b4e13fcf0f",
                "deletedDateTime": null,
                "classification": null,
                "createdDateTime": "2018-09-26T04:41:10Z",
                "creationOptions": [],
                "description": null,
                "displayName": "Business",
                "groupTypes": [],
                "mail": null,
                "mailEnabled": false,
                "mailNickname": "xxxx-redacted-88df-adf033b7f545",
                "onPremisesLastSyncDateTime": null,
                "onPremisesSecurityIdentifier": null,
                "onPremisesSyncEnabled": null,
                "preferredDataLocation": null,
                "proxyAddresses": [],
                "renewedDateTime": "2018-09-26T04:41:10Z",
                "resourceBehaviorOptions": [],
                "resourceProvisioningOptions": [],
                "securityEnabled": true,
                "visibility": null,
                "onPremisesProvisioningErrors": [],
                "owners": []
            },
            {
                "id": "xxxx-redacted-9316-a5acea4412d8",
                "deletedDateTime": null,
                "classification": null,
                "createdDateTime": "2018-09-26T04:19:29Z",
                "creationOptions": [],
                "description": null,
                "displayName": "DevOps",
                "groupTypes": [],
                "mail": null,
                "mailEnabled": false,
                "mailNickname": "xxxx-redacted-4f18-b2b1-e5a7b80d19ea",
                "onPremisesLastSyncDateTime": null,
                "onPremisesSecurityIdentifier": null,
                "onPremisesSyncEnabled": null,
                "preferredDataLocation": null,
                "proxyAddresses": [],
                "renewedDateTime": "2018-09-26T04:19:29Z",
                "resourceBehaviorOptions": [],
                "resourceProvisioningOptions": [],
                "securityEnabled": true,
                "visibility": null,
                "onPremisesProvisioningErrors": [],
                "owners": [
                    {
                        "@odata.type": "#microsoft.graph.user",
                        "id": "xxxx-redacted-8000-8cb9f0d497c9",
                        "deletedDateTime": null,
                        "accountEnabled": true,
                        "ageGroup": null,
                        "businessPhones": [],
                        "city": "xxxx",
                        "companyName": null,
                        "consentProvidedForMinor": null,
                        "country": "xxxx",
                        "createdDateTime": null,
                        "department": "Human Resources",
                        "displayName": "Adam G",
                        "employeeId": null,
                        "faxNumber": null,
                        "givenName": "Adam",
                        "jobTitle": "Senior Human Resource Manager",
                        "legalAgeGroupClassification": null,
                        "mail": null,
                        "mailNickname": "adamg",
                        "mobilePhone": "xxxx",
                        "onPremisesDistinguishedName": null,
                        "onPremisesDomainName": null,
                        "onPremisesImmutableId": null,
                        "onPremisesLastSyncDateTime": null,
                        "onPremisesSecurityIdentifier": null,
                        "onPremisesSamAccountName": null,
                        "onPremisesSyncEnabled": null,
                        "onPremisesUserPrincipalName": null,
                        "otherMails": [],
                        "passwordPolicies": "DisablePasswordExpiration",
                        "passwordProfile": null,
                        "officeLocation": "131/1105",
                        "postalCode": "98052",
                        "preferredLanguage": "en-US",
                        "proxyAddresses": [],
                        "refreshTokensValidFromDateTime": "2018-09-19T03:34:39Z",
                        "imAddresses": [],
                        "isResourceAccount": null,
                        "showInAddressList": null,
                        "state": "MH",
                        "streetAddress": "xxxxxxxe",
                        "surname": "Gily",
                        "usageLocation": "US",
                        "userPrincipalName": "adamg@xxxxx.onmicrosoft.com",
                        "userType": "Member",
                        "assignedLicenses": [],
                        "assignedPlans": [],
                        "onPremisesProvisioningErrors": [],
                        "onPremisesExtensionAttributes": {
                            "extensionAttribute1": null,
                            "extensionAttribute2": null,
                            "extensionAttribute3": null,
                            "extensionAttribute4": null,
                            "extensionAttribute5": null,
                            "extensionAttribute6": null,
                            "extensionAttribute7": null,
                            "extensionAttribute8": null,
                            "extensionAttribute9": null,
                            "extensionAttribute10": null,
                            "extensionAttribute11": null,
                            "extensionAttribute12": null,
                            "extensionAttribute13": null,
                            "extensionAttribute14": null,
                            "extensionAttribute15": null
                        },
                        "provisionedPlans": []
                    },
                    {
                        "@odata.type": "#microsoft.graph.user",
                        "id": "xxxx-redacted-4824-8013-4325f68e275d",
                        "deletedDateTime": null,
                        "accountEnabled": true,
                        "ageGroup": null,
                        "businessPhones": [],
                        "city": null,
                        "companyName": null,
                        "consentProvidedForMinor": null,
                        "country": null,
                        "createdDateTime": null,
                        "department": null,
                        "displayName": "groupownertest",
                        "employeeId": null,
                        "faxNumber": null,
                        "givenName": null,
                        "jobTitle": null,
                        "legalAgeGroupClassification": null,
                        "mail": null,
                        "mailNickname": "groupownertest",
                        "mobilePhone": null,
                        "onPremisesDistinguishedName": null,
                        "onPremisesDomainName": null,
                        "onPremisesImmutableId": null,
                        "onPremisesLastSyncDateTime": null,
                        "onPremisesSecurityIdentifier": null,
                        "onPremisesSamAccountName": null,
                        "onPremisesSyncEnabled": null,
                        "onPremisesUserPrincipalName": null,
                        "otherMails": [],
                        "passwordPolicies": null,
                        "passwordProfile": null,
                        "officeLocation": null,
                        "postalCode": null,
                        "preferredLanguage": null,
                        "proxyAddresses": [],
                        "refreshTokensValidFromDateTime": "2019-01-23T18:56:43Z",
                        "imAddresses": [],
                        "isResourceAccount": null,
                        "showInAddressList": null,
                        "state": null,
                        "streetAddress": null,
                        "surname": null,
                        "usageLocation": null,
                        "userPrincipalName": "groupownertest@XXXXX.onmicrosoft.com",
                        "userType": "Member",
                        "assignedLicenses": [],
                        "assignedPlans": [],
                        "onPremisesProvisioningErrors": [],
                        "onPremisesExtensionAttributes": {
                            "extensionAttribute1": null,
                            "extensionAttribute2": null,
                            "extensionAttribute3": null,
                            "extensionAttribute4": null,
                            "extensionAttribute5": null,
                            "extensionAttribute6": null,
                            "extensionAttribute7": null,
                            "extensionAttribute8": null,
                            "extensionAttribute9": null,
                            "extensionAttribute10": null,
                            "extensionAttribute11": null,
                            "extensionAttribute12": null,
                            "extensionAttribute13": null,
                            "extensionAttribute14": null,
                            "extensionAttribute15": null
                        },
                        "provisionedPlans": []
                    }
                ]
            }
        ]
    }
    

    更新 1(回答来自 cmets 的查询)

    成员和所有者都是导航属性/关系,而不是组的直接属性。您一次只能扩展一个。我将向您展示 3 个可以从 Microsoft Graph Explorer 中测试的快速 api 调用。

    仅扩展成员 - 这会按预期工作并返回组以及每个组的成员。

    GET https://graph.microsoft.com/v1.0/groups?$expand=members
    

    仅扩展所有者 - 这会按预期工作并返回组以及每个组的所有者。上面已经显示了示例响应。

    GET https://graph.microsoft.com/v1.0/groups?$expand=owners
    

    在一次调用中同时扩展成员和所有者

    GET https://graph.microsoft.com/v1.0/groups?$expand=members,owners
    

    回应

    您只能在一次调用中展开一个导航属性.. 看看错误消息,它非常直观

    {
        "error": {
            "code": "Request_BadRequest",
            "message": "The result of parsing $expand contained at least 2 items, but the maximum allowed is 1.",
            "innerError": {
                "request-id": "119cf794-af56-48a0-b415-4d52c2e60e98",
                "date": "2019-02-13T02:57:13"
            }
        }
    }
    

    UPDATE 2(回答有关从 cmets 一起展开和选择的查询)

    我认为您不能在查询中只使用 $select 和 $expand 来选择几列。这似乎是一个已知的限制。有关更多上下文,请参阅下面的两个链接

    1. Query Parameter Limitations - Microsoft Docs
    2. Another SO post 具体来说,在这篇 SO 帖子中,请查看来自 Marc LaFleur 的评论和来自 Dan Kershaw - MSFT 的答案

    【讨论】:

    • 感谢您的回复......如果我需要同时获取群组的所有者和群组成员......这是不工作https://graph.microsoft.com/v1.0/groups?$expand=owners, users
    • 不客气。成员和所有者都是导航属性..我认为您无法在一次调用中扩展它们..它会像https://graph.microsoft.com/v1.0/groups?$expand=owners,members 我会快速测试并更新我的答案
    • @AlexMan 我已经更新了我的答案,最后提供了更详细的信息(包括示例请求和响应)。
    • 感谢您最后我如何仅提及在所有者数组下返回所需的详细信息。假设我只想要所有者的 ID 和邮件详细信息,我们该怎么做。我已经看到了一个名为 $select 的选项,但它对我来说不起作用。我试过https://graph.microsoft.com/v1.0/groups?$expand=owners($select=id,mail)
    猜你喜欢
    • 1970-01-01
    • 2023-01-12
    • 1970-01-01
    • 2016-12-07
    • 1970-01-01
    • 1970-01-01
    • 2021-02-11
    • 2014-10-15
    • 1970-01-01
    相关资源
    最近更新 更多