> For the complete documentation index, see [llms.txt](https://docs.realmjoin.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.realmjoin.com/ja/zi-dong-hua/runbooks/runbook-references/org/security/list-admin-users.md).

# 管理者ユーザーの一覧表示

### 説明

組み込みの Entra ID ロールを保持しているユーザーと Service Principals を一覧表示し、管理者からロールへのレポートを作成します。必要に応じて、登録済みの認証方法について各管理者を照会し、MFA のカバレッジを評価します。

### 場所

組織 → セキュリティ → 管理ユーザーの一覧

**Runbook の完全名**

rjgit-org\_security\_list-admin-users

### 詳細

| プロパティ    | 値                                                                                       |
| -------- | --------------------------------------------------------------------------------------- |
| バージョン    | 1.2.4                                                                                   |
| 必要なモジュール | <p>RealmJoin.RunbookHelper (>= 0.8.9)<br>Microsoft.Graph.Authentication (>= 2.39.0)</p> |
| スケジュール可能 | いいえ                                                                                     |

### アクセス許可

#### アプリケーションのアクセス許可

* **種類**：Microsoft Graph
  * User.Read.All
    * *ロール保持者のプリンシパルを解決する際に、ユーザーの詳細を読み取ります*
  * Directory.Read.All
    * */directoryObjects を使用して、ロール保持者の principal id をユーザー、グループ、または Service Principals に解決します*
  * RoleManagement.Read.All
    * *ロール定義、ロール割り当て、および PIM の適格性スケジュールを一覧表示します*
  * RoleAssignmentSchedule.Read.Directory
    * *roleAssignmentScheduleInstances を読み取り、PIM 割り当ての終了日時をレポートします*
  * UserAuthenticationMethod.Read.All *（省略可能 — 機能: MFA 状態）*
    * *QueryMfaState が有効な場合（既定でオン）、各管理者の認証方法を読み取ります*

### パラメーター

#### ファイルにエクスポート

true に設定すると、レポートを Azure Storage Account にエクスポートします。

| プロパティ | 値    |
| ----- | ---- |
| 必須    | いいえ  |
| 既定値   | はい   |
| 種類    | ブール値 |

#### PimEligibleUntilInCSV

true に設定すると、CSV レポートに PIM の適格/有効期限情報を含めます。

| プロパティ | 値     |
| ----- | ----- |
| 必須    | いいえ   |
| 既定値   | False |
| 種類    | ブール値  |

#### ContainerName

CSV レポートをアップロードする Azure Storage コンテナーの名前。

| プロパティ    | 値                        |
| -------- | ------------------------ |
| 必須       | いいえ                      |
| 既定値      |                          |
| 種類       | 文字列                      |
| ポータルで非表示 | はい（Runbook のカスタマイズで事前設定） |

#### ResourceGroupName

Storage Account を含む Azure リソース グループの名前。

| プロパティ    | 値                        |
| -------- | ------------------------ |
| 必須       | いいえ                      |
| 既定値      |                          |
| 種類       | 文字列                      |
| ポータルで非表示 | はい（Runbook のカスタマイズで事前設定） |

#### StorageAccountName

アップロードに使用する Azure Storage Account の名前。

| プロパティ    | 値                        |
| -------- | ------------------------ |
| 必須       | いいえ                      |
| 既定値      |                          |
| 種類       | 文字列                      |
| ポータルで非表示 | はい（Runbook のカスタマイズで事前設定） |

#### Storage Account の場所

必要に応じて作成される Storage Account 用の Azure リージョン。

| プロパティ    | 値                        |
| -------- | ------------------------ |
| 必須       | いいえ                      |
| 既定値      |                          |
| 種類       | 文字列                      |
| ポータルで非表示 | はい（Runbook のカスタマイズで事前設定） |

#### Storage Account SKU

必要に応じて作成される Storage Account の SKU 名。

| プロパティ    | 値                        |
| -------- | ------------------------ |
| 必須       | いいえ                      |
| 既定値      |                          |
| 種類       | 文字列                      |
| ポータルで非表示 | はい（Runbook のカスタマイズで事前設定） |

#### QueryMfaState

「各管理者の MFA 状態を確認して報告する」（最終値: $true）または「管理者の MFA 状態を確認しない」（最終値: $false）を、実行するアクションとして選択できます。

| プロパティ | 値    |
| ----- | ---- |
| 必須    | いいえ  |
| 既定値   | はい   |
| 種類    | ブール値 |

**ポータルのオプション**

| ポータルオプション             | 値   |
| --------------------- | --- |
| 各管理者の MFA 状態を確認して報告する | はい  |
| 管理者の MFA 状態を確認しない     | いいえ |

#### TrustEmailMfa

true に設定すると、メールを有効な MFA 方法とみなします。

| プロパティ | 値     |
| ----- | ----- |
| 必須    | いいえ   |
| 既定値   | False |
| 種類    | ブール値  |

#### TrustPhoneMfa

true に設定すると、電話/SMS を有効な MFA 方法とみなします。

| プロパティ | 値     |
| ----- | ----- |
| 必須    | いいえ   |
| 既定値   | False |
| 種類    | ブール値  |

#### TrustSoftwareOathMfa

true に設定すると、ソフトウェア OATH トークンを有効な MFA 方法とみなします。

| プロパティ | 値    |
| ----- | ---- |
| 必須    | いいえ  |
| 既定値   | はい   |
| 種類    | ブール値 |

#### TrustWinHelloMFA

true に設定すると、Windows Hello for Business を有効な MFA 方法とみなします。

| プロパティ | 値     |
| ----- | ----- |
| 必須    | いいえ   |
| 既定値   | False |
| 種類    | ブール値  |

[Runbook Reference の概要に戻る](/ja/zi-dong-hua/runbooks/runbook-references.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.realmjoin.com/ja/zi-dong-hua/runbooks/runbook-references/org/security/list-admin-users.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
