You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用PowerShell内置工具查询msDS-User-Account-Control-Computed返回值异常

解决使用 adsisearcher 查询 msDS-User-Account-Control-Computed 返回0的问题

问题说明

需要用PowerShell的[adsisearcher](DirectorySearcher类)查询AD用户的msDS-User-Account-Control-Computed属性,不能使用Get-ADUser等AD模块cmdlet。但执行代码后返回值始终为0,且通过GetDirectoryEntry()无法获取该属性,即使设置SearchScope为Base也无效。该属性是构造属性,包含userAccountControl没有的标志(如LOCK_OUT、PASSWORD_EXPIRED),普通用户的预期值应与userAccountControl(512)一致或包含额外标志。

原因分析

msDS-User-Account-Control-Computed是动态构造属性,并非存储在AD数据库中的静态属性,而是由域控制器在查询时实时计算生成的:

  • 这类属性必须在搜索时显式指定加载,否则域控制器不会返回;
  • 默认的Subtree搜索作用域可能因LDAP优化策略,无法触发构造属性的计算逻辑;
  • GetDirectoryEntry()返回的是AD对象的绑定实例,仅包含持久化存储的属性,不会返回构造属性。

解决方案

使用Base作用域直接绑定到用户对象,显式请求该构造属性,确保域控制器正确计算并返回值。

正确代码示例

# 1. 查询当前用户的DistinguishedName
$userSearcher = [adsisearcher] "(sAMAccountName=$env:USERNAME)"
$userResult = $userSearcher.FindOne()
$userDN = $userResult.Properties['distinguishedName'][0]

# 2. 构造Base作用域查询,明确请求目标构造属性
$computedSearcher = [adsisearcher]::new()
$computedSearcher.SearchRoot = "LDAP://$userDN"
$computedSearcher.SearchScope = [System.DirectoryServices.SearchScope]::Base
$computedSearcher.PropertiesToLoad.Add('msDS-User-Account-Control-Computed') | Out-Null

# 3. 执行查询并获取结果
$computedResult = $computedSearcher.FindOne()
$computedValue = $computedResult.Properties['msDS-User-Account-Control-Computed'][0]

# 输出结果
Write-Host "msDS-User-Account-Control-Computed 值: $computedValue"

关键注意事项

  • 确保属性名拼写准确:msDS-User-Account-Control-Computed(LDAP属性名不区分大小写,但建议使用官方标准拼写);
  • Base作用域是触发构造属性计算的可靠方式,因为它直接针对单个对象请求;
  • 不要通过GetDirectoryEntry()获取该属性,构造属性仅会在LDAP搜索请求中返回;
  • 确认域功能级别至少为Windows Server 2003(该属性从该版本开始支持)。

内容的提问来源于stack exchange,提问作者stackprotector

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 05:04:59