管理 Azure 注册Manage Azure registration

适用于 Azure Stack HCI v20H2Applies to Azure Stack HCI v20H2

创建 Azure Stack HCI 群集后,必须向 Azure Arc 注册该群集。群集注册后,会定期在本地群集和云之间同步信息。Once you've created an Azure Stack HCI cluster, you must register the cluster with Azure Arc. Once the cluster is registered, it periodically syncs information between the on-premises cluster and the cloud. 本主题介绍如何了解注册状态并在可以解除群集授权时注销群集。This topic explains how to understand your registration status and unregister your cluster when you're ready to decommission it.

了解注册状态Understanding registration status

若要了解注册状态,请使用 Get-AzureStackHCI PowerShell cmdlet 和 ClusterStatusRegistrationStatusConnectionStatus 属性。To understand registration status, use the Get-AzureStackHCI PowerShell cmdlet and the ClusterStatus, RegistrationStatus, and ConnectionStatus properties. 例如,在安装 Azure Stack HCI 操作系统之后、创建或加入群集之前,ClusterStatus 属性显示为“尚未”状态:For example, after installing the Azure Stack HCI operating system, before creating or joining a cluster, the ClusterStatus property shows "not yet" status:

创建群集前的 Azure 注册状态

创建群集后,只有 RegistrationStatus 显示“尚未”状态:Once the cluster is created, only RegistrationStatus shows "not yet" status:

创建群集后的 Azure 注册状态

根据 Azure 在线服务条款,Azure Stack HCI 需要在安装后 30 天内进行注册。Azure Stack HCI needs to register within 30 days of installation per the Azure Online Services Terms. 如果在 30 天后未群集化,则 ClusterStatus 将显示 OutOfPolicy,如果 30 天后未注册,则 RegistrationStatus 将显示 OutOfPolicyIf not clustered after 30 days, the ClusterStatus will show OutOfPolicy, and if not registered after 30 days, the RegistrationStatus will show OutOfPolicy.

注册群集后,可以查看 ConnectionStatusLastConnected 时间(通常在最后一天内),除非群集暂时与 Internet 断开连接。Once the cluster is registered, you can see the ConnectionStatus and LastConnected time, which is usually within the last day unless the cluster is temporarily disconnected from the Internet. Azure Stack HCI 群集最多可以连续 30 天完全脱机运行。An Azure Stack HCI cluster can operate fully offline for up to 30 consecutive days.

注册后的 Azure 注册状态

如果超出允许的最长时间,则 ConnectionStatus 将显示 OutOfPolicyIf that maximum period is exceeded, the ConnectionStatus will show OutOfPolicy.

Azure Active Directory 权限Azure Active Directory permissions

除了在订阅中创建 Azure 资源外,注册 Azure Stack HCI 还可以在 Azure Active Directory 租户中创建一个概念类似于用户的应用标识。In addition to creating an Azure resource in your subscription, registering Azure Stack HCI creates an app identity, conceptually similar to a user, in your Azure Active Directory tenant. 应用标识会继承群集名称。The app identity inherits the cluster name. 此标识代表订阅中的 Azure Stack HCI 云服务(如果适用)执行操作。This identity acts on behalf on the Azure Stack HCI cloud service, as appropriate, within your subscription.

如果运行 Register-AzureStackHCI 的用户是 Azure Active Directory 管理员或已被委派了足够的权限,则这一切都会自动发生,无需执行其他操作。If the user who runs Register-AzureStackHCI is an Azure Active Directory administrator or has been delegated sufficient permissions, this all happens automatically, and no additional action is required. 否则,可能需要 Azure Active Director 管理员的批准才能完成注册。If not, approval may be needed from your Azure Active Directory administrator to complete registration. 你的管理员可以向应用显式授予同意,也可以委派权限,使你可以向应用授予同意:Your administrator can either explicitly grant consent to the app, or they can delegate permissions so that you can grant consent to the app:

Azure Active Directory 权限和标识图

若要授予同意,请打开 portal.azure.cn,并使用对 Azure Active Directory 具有足够权限的 Azure 帐户进行登录。To grant consent, open portal.azure.cn and sign in with an Azure account that has sufficient permissions on the Azure Active Directory. 依次导航到“Azure Active Directory”、“应用注册”。 Navigate to Azure Active Directory, then App registrations. 选择以你的群集命名的应用标识,然后导航到“API 权限”。Select the app identity named after your cluster and navigate to API permissions.

应用需要两种权限:The app requires two permissions:

https://azurestackhci-usage.trafficmanager.net/AzureStackHCI.Census.Sync

https://azurestackhci-usage.trafficmanager.net/AzureStackHCI.Billing.Sync

向 Azure Active Directory 管理员寻求批准可能需要一些时间,因此 Register-AzureStackHCI cmdlet 会退出,并将注册状态保持为“待管理员同意”,即完成部分注册。Seeking approval from your Azure Active Directory administrator could take some time, so the Register-AzureStackHCI cmdlet will exit and leave the registration in status "pending admin consent," i.e. partially completed. 授予同意后,只需重新运行 Register-AzureStackHCI 即可完成注册。Once consent has been granted, simply re-run Register-AzureStackHCI to complete registration.

使用 Azure 注销 Azure Stack HCIUnregister Azure Stack HCI with Azure

准备好解除 Azure Stack HCI 群集的授权后,请使用 Unregister-AzStackHCI cmdlet 进行注销。When you're ready to decommission your Azure Stack HCI cluster, use the Unregister-AzStackHCI cmdlet to unregister. 这将停止通过 Azure Arc 进行的所有监视、支持和计费功能。将删除代表群集的 Azure 资源和 Azure Active Directory 应用标识,但不会删除该资源组,因为它可能包含其他不相关的资源。This stops all monitoring, support, and billing functionality through Azure Arc. The Azure resource representing the cluster and the Azure Active Directory app identity are deleted, but the resource group is not, because it may contain other unrelated resources.

如果在群集节点上运行 Unregister-AzStackHCI cmdlet,请使用以下语法并指定你的 Azure 订阅 ID 以及要注销的 Azure Stack HCI 群集的资源名称:If running the Unregister-AzStackHCI cmdlet on a cluster node, use this syntax and specify your Azure subscription ID as well as the resource name of the Azure Stack HCI cluster you wish to unregister:

Unregister-AzStackHCI -SubscriptionId "e569b8af-6ecc-47fd-a7d5-2ac7f23d8bfe" -ResourceName HCI001

系统将提示你在另一台设备(如电脑或手机)上访问 microsoft.com/deviceloginchina,输入代码,然后在其中登录以进行 Azure 身份验证。You'll be prompted to visit microsoft.com/deviceloginchina on another device (like your PC or phone), enter the code, and sign in there to authenticate with Azure.

如果从管理电脑运行 cmdlet,则还需要指定群集中服务器的名称:If running the cmdlet from a management PC, you'll also need to specify the name of a server in the cluster:

Unregister-AzStackHCI -ComputerName ClusterNode1 -SubscriptionId "e569b8af-6ecc-47fd-a7d5-2ac7f23d8bfe" -ResourceName HCI001

将弹出一个交互式 Azure 登录窗口。An interactive Azure login window will pop up. 显示的确切提示将因安全设置(例如双重身份验证)而异。The exact prompts you see will vary depending on your security settings (e.g. two-factor authentication). 按照提示进行登录。Follow the prompts to log in.

后续步骤Next steps

如需相关信息,另请参阅:For related information, see also: