Catatan
Akses ke halaman ini memerlukan otorisasi. Anda dapat mencoba masuk atau mengubah direktori.
Akses ke halaman ini memerlukan otorisasi. Anda dapat mencoba mengubah direktori.
Dalam artikel ini, Anda mempelajari cara menjalankan skrip Warisan Azure AD PowerShell di Microsoft Entra PowerShell menggunakan mode kompatibilitas, memungkinkan migrasi skrip yang mulus dengan perubahan minimal. Proses ini memungkinkan Anda untuk transisi dengan lancar ke modul baru sambil mempertahankan alur kerja otomatisasi yang ada, memastikan efisiensi dan kepatuhan berkelanjutan dengan alat yang diperbarui.
Microsoft Entra PowerShell memiliki kompatibilitas lebih dari 98% dengan modul Azure AD PowerShell. Dalam mode kompatibilitas, Anda dapat menjalankan skrip PowerShell Azure AD yang sudah ada dengan modifikasi minimal menggunakan Microsoft Entra PowerShell dengan menggunakan Enable-EntraAzureADAlias perintah . Untuk menemukan cmdlet Azure AD PowerShell dan MSOnline yang setara di Microsoft Entra PowerShell, gunakan peta cmdlet Azure AD PowerShell ke Microsoft Entra PowerShell.
Gunakan mode kompatibilitas dengan Enable-EntraAzureADAlias
Enable-EntraAzureADAlias Cmdlet memungkinkan mode kompatibilitas melalui alias. Secara default, Enable-EntraAzureADAlias hanya mengaktifkan alias kompatibilitas untuk sesi PowerShell Microsoft Entra saat ini. Untuk informasi selengkapnya, lihat dokumentasi referensi Enable-EntraAzureADAlias .
Untuk menggunakan Microsoft Entra PowerShell dengan skrip AzureAD PowerShell yang sudah ada, ganti Connect-AzureAD perintah dengan tiga baris yang disediakan. Ketiga baris ini adalah awal dari skrip AzureAD PowerShell Anda yang dimigrasikan.
Import-Module -Name Microsoft.Entra.Applications
Connect-Entra -Scopes 'Application.Read.All' #Replaces Connect-AzureAD for auth
Enable-EntraAzureADAlias #enable aliasing
Get-AzureADApplication -Top 2
Contoh
Dalam contoh ini, Anda menjalankan skrip yang mengekspor aplikasi dengan rahasia kedaluwarsa menggunakan Microsoft Entra PowerShell. Contoh ini mengasumsikan bahwa modul PowerShell Microsoft Entra sudah diinstal.
Contoh skrip berikut adalah skrip AzureAD PowerShell asli.
Connect-AzureAD
$applications = Get-AzureADApplication -All $true
$Logs = @()
Write-Host "I would like to see the Applications with the Secrets and Certificates that expire in the next X amount of Days? <<Replace X with the number of days. The answer should be ONLY in Numbers>>" -ForegroundColor Green
$Days = Read-Host
Write-Host "Would you like to see Applications with already expired secrets or certificates as well? <<Answer with [Yes] [No]>>" -ForegroundColor Green
$alreadyExpired = Read-Host
$now = Get-Date
foreach ($app in $applications) {
$appName = $app.DisplayName
$appID = $app.objectid
$applID = $app.AppId
$appCreds = Get-AzureADApplication -ObjectId $appID | Select-Object -Property PasswordCredentials, KeyCredentials
$secret = $appCreds.PasswordCredentials
$cert = $appCreds.KeyCredentials
Catatan: Cuplikan kode ini dipersingkat untuk keterbacaan. Lihat sampel lengkap untuk detailnya.
Untuk menggunakan skrip Anda dengan modul PowerShell Microsoft Entra, ganti Connect-AzureAD cmdlet dengan tiga baris yang disediakan dalam cuplikan. Anda tidak perlu menulis ulang seluruh skrip.
Skrip berikut adalah skrip yang dimigrasikan.
Import-Module -Name Microsoft.Entra.Users
Connect-Entra #Replaces Connect-AzureAD for auth
Enable-EntraAzureADAlias #Activate aliasing
$applications = Get-AzureADApplication -All $true
$logs = @()
Write-Host "I would like to see the Applications with the Secrets and Certificates that expire in the next X amount of Days? <<Replace X with the number of days. The answer should be ONLY in Numbers>>" -ForegroundColor Green
$days = Read-Host
Write-Host "Would you like to see Applications with already expired secrets or certificates as well? <<Answer with [Yes] [No]>>" -ForegroundColor Green
$alreadyExpired = Read-Host
$now = Get-Date
foreach ($app in $applications) {
$appName = $app.DisplayName
$appID = $app.Objectid
$applID = $app.AppId
$appCreds = Get-AzureADApplication -ObjectId $appID | Select-Object -Property PasswordCredentials, KeyCredentials
$secret = $appCreds.PasswordCredentials
$cert = $appCreds.KeyCredentials
Catatan: Cuplikan kode ini dipersingkat untuk keterbacaan. Lihat sampel lengkap yang dimodifikasi untuk detailnya.
Uji kompatibilitas dengan perintah Test-EntraScript
Cmdlet Test-EntraScript memverifikasi apakah skrip dengan perintah Azure AD PowerShell berfungsi dengan modul PowerShell Microsoft Entra. Jika ada masalah kompatibilitas, ia mencantumkannya, termasuk nomor baris, jenis masalah, perintah yang tidak kompatibel, dan cuplikan kode tertentu.
Masalah yang diketahui
Saat bermigrasi dari modul Azure AD PowerShell ke Microsoft Entra PowerShell, Anda mungkin mengalami beberapa masalah yang diketahui.
- Parameter
-Filtermungkin tidak berfungsi dengan benar. - Parameter
-SearchStringmungkin tidak berfungsi dengan benar. - Objek output dapat sedikit berbeda dengan objek output AzureAD.