# 如何透過 Microsoft Graph PowerShell 取得使用者的 Department 資料

由於 Microsoft Graph PowerShell 的 `Microsoft.Graph` 模組背後是呼叫 [Microsoft Graph REST API v1.0 endpoint](https://learn.microsoft.com/en-us/graph/api/overview?view=graph-rest-1.0&WT.mc_id=DT-MVP-4015686)，所以有許多 Cmdlets 命令都受限於 Microsoft Graph REST API 的設計，因此使用上相當不便。當我在用 [Get-MgUser](https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.users/get-mguser?view=graph-powershell-1.0&WT.mc_id=DT-MVP-4015686) Cmdlet 取得使用者資料時，一直都沒辦法取得 `Department` 屬性資料，今天終於給我研究出方法了。

![image](https://stwillblogassets.blob.core.windows.net/files/images/external/stwillblogassets.blob.core.windows.net/0e21c34a44a3d15517ab-efa81a89-5535-4138-9b02-6365bff417ec.webp)

在 [List users - Microsoft Graph v1.0](https://learn.microsoft.com/en-us/graph/api/user-list?view=graph-rest-1.0&WT.mc_id=DT-MVP-4015686&tabs=http#:~:text=By%20default%2C%20only,givenName%2CpostalCode.) 有一段說明是這樣寫的：

> By default, only a limited set of properties are returned (`businessPhones`, `displayName`, `givenName`, `id`, `jobTitle`, `mail`, `mobilePhone`, `officeLocation`, `preferredLanguage`, `surname`, and `userPrincipalName`).To return an alternative property set, specify the desired set of user properties using the OData `$select` query parameter. For example, to return `displayName`, `givenName`, and `postalCode`, add the following to your query `$select=displayName,givenName,postalCode`.

也因為這個原因，害我好幾個月以來一直找不到方法可以取得使用者的部門資料，我下的命令是這樣：

```powershell
Get-MgUser -Filter "UserPrincipalName eq 'user@example.com'" | select Id,UserPrincipalName,DisplayName,Mail,UserType,Department
```

你將會發現，回應的結果中 `Department` 屬性是空的！

### 使用 Microsoft.Graph 模組

由於我一直以來都使用 [Microsoft.Graph](https://www.powershellgallery.com/packages/Microsoft.Graph/) 模組在執行命令，無論如何先升級到[最新版](https://www.powershellgallery.com/packages/Microsoft.Graph/)再說：

```powershell
Update-Module Microsoft.Graph
```

今天我找到了一個解決方案，那就是要額外加上 `-Property` 或 `-Select` 明確指明要輸出哪些屬性，這樣就可以拿到資料了！

```powershell
Get-MgUser -Filter "UserPrincipalName eq 'user@example.com'" -Select Id,UserPrincipalName,DisplayName,Mail,UserType,Department | select Id,UserPrincipalName,DisplayName,Mail,UserType,Department
```

這個問題在 PowerShell 的文件中完全沒有提及！😒

### 安裝 Microsoft.Graph.Beta 模組

這個問題已經在 [Microsoft.Graph.Beta](https://www.powershellgallery.com/packages/Microsoft.Graph.Beta/) 被解決了，所以你可以安裝這個模組來使用：

```powershell
Install-Module Microsoft.Graph.Beta -Scope CurrentUser
```

> 備註: `Microsoft.Graph.Beta` 背後是呼叫 [Microsoft Graph REST API beta endpoint](https://learn.microsoft.com/en-us/graph/api/overview?view=graph-rest-beta&preserve-view=true&WT.mc_id=DT-MVP-4015686) 喔！

然後很直覺的使用這個命令下去執行即可：

```powershell
Get-MgBetaUser -Filter "UserPrincipalName eq 'will.huang@miniasp.com'" | select Id,UserPrincipalName,DisplayName,Mail,UserType,Department
```

> 注意: 使用 [Get-MgBetaUser](https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.beta.users/get-mgbetauser?view=graph-powershell-beta&WT.mc_id=DT-MVP-4015686) 可以回傳所有屬性，其中包含重要的 `AssignedLicenses` 屬性！

### 總結

今後我不會再用 `Microsoft.Graph` 模組了，改用 `Microsoft.Graph.Beta` 模組才是王道！👍

### 相關連結

-   [The get-mguser command shows department but not the value - Microsoft Q&A](https://learn.microsoft.com/en-us/answers/questions/973533/the-get-mguser-command-shows-department-but-not-th?WT.mc_id=DT-MVP-4015686)
-   [Get-MgUser (Microsoft.Graph.Users) | Microsoft Learn](https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.users/get-mguser?view=graph-powershell-1.0&WT.mc_id=DT-MVP-4015686)
-   [Get-MgBetaUser (Microsoft.Graph.Beta.Users) | Microsoft Learn](https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.beta.users/get-mgbetauser?view=graph-powershell-beta&WT.mc_id=DT-MVP-4015686)
-   [List users - Microsoft Graph v1.0 | Microsoft Learn](https://learn.microsoft.com/en-us/graph/api/user-list?view=graph-rest-1.0&WT.mc_id=DT-MVP-4015686&tabs=http)
-   [Error handling and troubleshooting cmdlets | Microsoft Learn](https://learn.microsoft.com/en-us/powershell/microsoftgraph/troubleshooting?view=graph-powershell-1.0&WT.mc_id=DT-MVP-4015686)
-   [Select-MgProfile: The term ‘Select-MgProfile’ is not recognized Error](https://o365reports.com/2023/07/12/the-term-select-mgprofile-is-not-recognized-error/)
