快速入门:使用 REST API 创建管理组Quickstart: Create a management group with REST API

管理组是一些容器,可以帮助跨多个订阅管理访问权限、策略和符合性。Management groups are containers that help you manage access, policy, and compliance across multiple subscriptions. 可以创建这些容器来构建可以与 Azure PolicyAzure 基于角色的访问控制配合使用的有效且高效的层次结构。Create these containers to build an effective and efficient hierarchy that can be used with Azure Policy and Azure Role Based Access Controls. 若要详细了解管理组,请参阅使用 Azure 管理组整理资源For more information on management groups, see Organize your resources with Azure management groups.

在目录中创建的第一个管理组可能需要最多 15 分钟才能完成。The first management group created in the directory could take up to 15 minutes to complete. 一些进程会首次运行以在 Azure 中为目录设置管理组服务。There are processes that run the first time to set up the management groups service within Azure for your directory. 在进程完成后将显示通知。You receive a notification when the process is complete. 有关详细信息,请参阅管理组的初始设置For more information, see initial setup of management groups.

先决条件Prerequisites

  • 如果没有 Azure 订阅,请在开始前创建一个试用帐户If you don't have an Azure subscription, create a trial account before you begin.

  • 安装 ARMClient(如果尚未安装)。If you haven't already, install ARMClient. 该工具可将 HTTP 请求发送到基于 Azure 资源管理器的 REST API。It's a tool that sends HTTP requests to Azure Resource Manager-based REST APIs. 你也可以使用 REST 文档中的“试用”功能,或者使用 PowerShell 的 Invoke-RestMethodPostman 等工具。Alternatively, you can use the "Try It" feature in REST documentation or tooling like PowerShell's Invoke-RestMethod or Postman.

  • 如果未启用层次结构保护,则租户中的任何 Azure AD 用户即使未分配有管理组写入权限,也可创建管理组。Any Azure AD user in the tenant can create a management group without the management group write permission assigned to that user if hierarchy protection isn't enabled. 这个新的管理组将成为根管理组的子级或默认管理组,并将为创建者分配“所有者”角色。This new management group becomes a child of the Root Management Group or the default management group and the creator is given an "Owner" role assignment. 管理组服务允许此功能,因此不需要在根级别分配角色。Management group service allows this ability so that role assignments aren't needed at the root level. 创建根管理组时,用户没有访问权限。No users have access to the Root Management Group when it's created. 为避免在查找 Azure AD 全局管理员以开始使用管理组方面遇到阻碍,我们允许在根级别创建初始管理组。To avoid the hurdle of finding the Azure AD Global Admins to start using management groups, we allow the creation of the initial management groups at the root level.

在 REST API 中创建Create in REST API

对于 REST API,请使用管理组 - 创建或更新终结点来创建新的管理组。For REST API, use the Management Groups - Create or Update endpoint to create a new management group. 在本例中,管理组 groupId 为 Contoso。In this example, the management group groupId is Contoso.

  • REST API URIREST API URI

    PUT https://management.chinacloudapi.cn/providers/Microsoft.Management/managementGroups/Contoso?api-version=2020-02-01
    
  • 无请求正文No Request Body

groupId 是要创建的唯一标识符。The groupId is a unique identifier being created. 此 ID 由其他命令用来引用此组,并且以后无法更改。This ID is used by other commands to reference this group and it can't be changed later.

如果希望管理组在 Azure 门户中显示不同的名称,请在请求正文中添加 properties.displayName 属性。If you want the management group to show a different name within the Azure portal, add the properties.displayName property in the request body. 例如,如果要创建一个 groupId 为 Contoso 且显示名称为“Contoso Group”的管理组,需要使用以下终结点和请求正文 :For example, to create a management group with the groupId of Contoso and the display name of Contoso Group, use the following endpoint and request body:

  • REST API URIREST API URI

    PUT https://management.chinacloudapi.cn/providers/Microsoft.Management/managementGroups/Contoso?api-version=2020-02-01
    
  • 请求正文Request Body

    {
      "properties": {
        "displayName": "Contoso Group"
      }
    }
    

在上述示例中,新的管理组是在根管理组下创建的。In the preceding examples, the new management group is created under the root management group. 若要指定其他管理组作为父级,请使用 properties.parent.id 属性。To specify a different management group as the parent, use the properties.parent.id property.

  • REST API URIREST API URI

    PUT https://management.chinacloudapi.cn/providers/Microsoft.Management/managementGroups/Contoso?api-version=2020-02-01
    
  • 请求正文Request Body

    {
      "properties": {
        "displayName": "Contoso Group",
        "parent": {
          "id": "/providers/Microsoft.Management/managementGroups/HoldingGroup"
        }
      }
    }
    

清理资源Clean up resources

若要删除上面创建的管理组,请使用管理组 - 删除终结点:To remove the management group created above, use the Management Groups - Delete endpoint:

  • REST API URIREST API URI

    DELETE https://management.chinacloudapi.cn/providers/Microsoft.Management/managementGroups/Contoso?api-version=2020-02-01
    
  • 无请求正文No Request Body

后续步骤Next steps

在本快速入门中,你创建了一个管理组来整理资源层次结构。In this quickstart, you created a management group to organize your resource hierarchy. 管理组可以包含订阅或其他管理组。The management group can hold subscriptions or other management groups.

要详细了解管理组以及如何管理资源层次结构,请继续执行以下操作:To learn more about management groups and how to manage your resource hierarchy, continue to: