entra-id
powershell
mg-graph
]
using OData any() to filter proxyAddresses in Graph API
Notes & motivation
I constantly forget why I did that thing or the other 😆. Since I already had notes on querying non‑empty extension attributes, I figured I’d extend that topic. The next thing I needed to solve was searching for proxyAddresses on synchronized objects.
The filter
For on‑premises synchronized objects, this part is easy; just filter on
onPremisesSyncEnabled eq true.
For proxyAddresses the documentation states:
Requires $select to retrieve. Supports $filter (eq, not, ge, le, startsWith, endsWith, /$count eq 0, /$count ne 0).
The tricky part is that proxyAddresses is multivalued. This is where the Graph OData documentation helps.
The any operator iteratively applies a Boolean expression to each item of a collection and returns true if the expression is true for at least one item of the collection, otherwise it returns false.
The documentation includes also some examples. For example, the imAddresses property of the user resource contains a collection of String primitive types. The following query retrieves only users with at least one imAddress of admin@contoso.com.
Import-Module Microsoft.Graph.Users
Get-MgUser -Filter "imAddresses/any(i:i eq 'admin@contoso.com')"
And there is even an example for proxyAddresses with advanced query capabilities
~/users?$filter=proxyAddresses/any(p:endswith(p,'contoso.com'))
In practice, this filter matches an object if at least one value in proxyAddresses ends with contoso.com. The p variable represents a single item from the multi‑value collection and is used inside the endsWith() function.
The command
The resulting command is then
Get-MgUser -Filter "proxyAddresses/any(p:endsWith(p,'@contoso.com')) and onPremisesSyncEnabled eq true" `
-ConsistencyLevel eventual `
-CountVariable countvar `
-All
The ConsistencyLevel and CountVariable parameters are required by advanced query capabilities.