双向信任域下跨域添加AD组成员PowerShell命令报错排查
Root Cause
Your command targets DomainA's domain controller via the -Server parameter. When resolving the -Members value, the cmdlet only searches DomainA's directory—since UserB resides in DomainB, it can't find the object, even with a two-way trust. PowerShell 4's Add-ADGroupMember has limited automatic cross-domain resolution unless you explicitly point it to the trusted domain or use a forest-wide unique identifier.
Solutions
1. Retrieve the User Object from DomainB First
Fetch UserB's AD object directly from DomainB's DC, then pass the object to Add-ADGroupMember. This ensures the cmdlet has a valid reference to the user, regardless of which domain's DC you target for the group.
# Get UserB from DomainB's DC $userB = Get-ADUser -Identity UserB -Server "domaincontroller.DomainB.com" # Add UserB to GroupA in DomainA Add-ADGroupMember -Identity GroupA -Members $userB -Server "domaincontroller.DomainA.com"
2. Use UserB's Distinguished Name (DN)
The Distinguished Name is unique across the entire AD forest. Providing it directly allows the DomainA DC to resolve the user via the two-way trust, as it can look up the DN in the trusted domain.
Add-ADGroupMember -Identity GroupA -Members "CN=UserB,OU=YourUsersOU,DC=DomainB,DC=com" -Server "domaincontroller.DomainA.com"
Replace the OU and domain components with UserB's actual DN.
3. Target a Global Catalog Server
Global Catalog servers store partial replicas of all domains in the forest. Using one (append port 3268 to the server name) lets the cmdlet resolve UserB's identity across domains.
Add-ADGroupMember -Identity GroupA -Members UserB@DomainB.com -Server "domaincontroller.DomainA.com:3268"
Why Your Original Commands Failed
- Using
UserB@DomainB.comorDomainB/UserBwith-Server DomainA.comtells the cmdlet to search only DomainA's directory for the user. It won't automatically query DomainB unless prompted via the methods above. - PowerShell 4's AD module lacks some of the cross-domain resolution improvements present in later versions (e.g., PowerShell 5.1+), making explicit object retrieval or DN usage more reliable.
内容的提问来源于stack exchange,提问作者omoko

