创建用来组织和管理资源的管理组Create management groups for resource organization and management

管理组是一些容器,可以帮助跨多个订阅管理访问权限、策略和符合性。Management groups are containers that help you manage access, policy, and compliance across multiple subscriptions. 可以创建这些容器来构建可以与 Azure PolicyAzure 基于角色的访问控制配合使用的有效且高效的层次结构。Create these containers to build an effective and efficient hierarchy that can be used with Azure Policy and Azure Role Based Access Controls. 若要详细了解管理组,请参阅使用 Azure 管理组整理资源For more information on management groups, see Organize your resources with Azure management groups.

在目录中创建的第一个管理组可能需要最多 15 分钟才能完成。The first management group created in the directory could take up to 15 minutes to complete. 一些进程会首次运行以在 Azure 中为目录设置管理组服务。There are processes that run the first time to set up the management groups service within Azure for your directory. 在进程完成后将显示通知。You receive a notification when the process is complete. 有关详细信息,请参阅管理组的初始设置For more information, see initial setup of management groups.

创建管理组Create a management group

租户中的任何 Azure AD 用户都可以创建管理组,即使该用户未分配有管理组写入权限。Any Azure AD user in the tenant can create a management group without the management group write permission assigned to that user. 此新管理组将是根管理组的子组,并且创建者将获得“所有者”角色分配。This new management group will be a child of the Root Management Group and the creator will be given an "Owner" role assignment. 管理组服务允许此功能,因此不需要在根级别分配角色。Management group service allows this ability so that role assignments aren't needed at the root level. 创建根管理组时,没有用户拥有对该组的访问权限。No users have access to the Root Management Group when it's created. 为了避免寻找 Azure AD 全局管理员以开始使用管理组的障碍,我们允许在根级别下创建初始管理组To avoid the hurdle of finding the Azure AD Global Admins to start using management groups, we allow the creation of the initial management groups at the root
level.

可以使用门户、Azure 资源管理器模板、PowerShell 或 Azure CLI 创建管理组。You can create the management group by using the portal, a Azure Resource Manager template, PowerShell, or Azure CLI.

在门户中创建Create in portal

  1. 登录到 Azure 门户Log into the Azure portal.

  2. 选择“所有服务” > “管理 + 治理” 。Select All services > Management + governance.

  3. 选择“管理组”。Select Management Groups.

  4. 选择“+ 添加管理组”。****Select + Add management group.

    管理组操作页

  5. 填写管理组 ID 字段。Fill in the management group ID field.

    • “管理组 ID”是用来在此管理组上提交命令的目录唯一标识符。The Management Group ID is the directory unique identifier that is used to submit commands on this management group. 此标识符一旦创建便无法再编辑,因为它用来在整个 Azure 系统中标识这个组。This identifier isn't editable after creation as it is used throughout the Azure system to identify this group. 根管理组是自动创建的,其 ID 为 Azure Active Directory ID。The root management group is automatically created with an ID that is the Azure Active Directory ID. 对于所有其他管理组,请分配唯一的 ID。For all other management groups, assign a unique ID.
    • 显示名称字段是在 Azure 门户中显示的名称。The display name field is the name that is displayed within the Azure portal. 创建管理组时,单独的显示名称是一个可选字段,并且可以随时更改A separate display name is an optional field when creating the management group and can be changed at any
      time.

    用于创建新管理组的“选项”窗格

  6. 选择“保存” 。Select Save.

在 PowerShell 中创建Create in PowerShell

在 PowerShell 中,使用 New-AzManagementGroup cmdlet 创建新的管理组。For PowerShell, use the New-AzManagementGroup cmdlet to create a new management group.

New-AzManagementGroup -GroupName 'Contoso'

GroupName 是要创建的唯一标识符。The GroupName is a unique identifier being created. 此 ID 由其他命令用来引用此组,并且以后无法更改。This ID is used by other commands to reference this group and it can't be changed later.

如果希望管理组在 Azure 门户中显示一个不同的名称,请添加 DisplayName 参数。If you want the management group to show a different name within the Azure portal, add the DisplayName parameter. 例如,若要创建 GroupName 为 Contoso 且显示名称为“Contoso Group”的管理组,请使用以下 cmdlet:For example, to create a management group with the GroupName of Contoso and the display name of "Contoso Group", use the following cmdlet:

New-AzManagementGroup -GroupName 'Contoso' -DisplayName 'Contoso Group'

在上述示例中,新的管理组是在根管理组下创建的。In the preceding examples, the new management group is created under the root management group. 若要指定一个不同的管理组作为父级,请使用 ParentId 参数。To specify a different management group as the parent, use the ParentId parameter.

$parentGroup = Get-AzManagementGroup -GroupName Contoso
New-AzManagementGroup -GroupName 'ContosoSubGroup' -ParentId $parentGroup.id

在 Azure CLI 中创建Create in Azure CLI

在 Azure CLI 中,使用 az account management-group create 命令创建新的管理组。For Azure CLI, use the az account management-group create command to create a new management group.

az account management-group create --name Contoso

name 是要创建的唯一标识符。The name is a unique identifier being created. 此 ID 由其他命令用来引用此组,并且以后无法更改。This ID is used by other commands to reference this group and it can't be changed later.

如果希望管理组在 Azure 门户中显示一个不同的名称,请添加 display-name 参数。If you want the management group to show a different name within the Azure portal, add the display-name parameter. 例如,若要创建 GroupName 为 Contoso 且显示名称为“Contoso Group”的管理组,请使用以下命令:For example, to create a management group with the GroupName of Contoso and the display name of "Contoso Group", use the following command:

az account management-group create --name Contoso --display-name 'Contoso Group'

在上述示例中,新的管理组是在根管理组下创建的。In the preceding examples, the new management group is created under the root management group. 若要指定一个不同的管理组作为父级,请使用 parent 参数并提供父组的名称。To specify a different management group as the parent, use the parent parameter and provide the name of the parent group.

az account management-group create --name ContosoSubGroup --parent Contoso

后续步骤Next steps

若要了解有关管理组的详细信息,请参阅:To learn more about management groups, see: