使用PowerShell内置工具查询msDS-User-Account-Control-Computed返回值异常
解决使用
adsisearcher 查询 msDS-User-Account-Control-Computed 返回0的问题 问题说明
需要用PowerShell的[adsisearcher](DirectorySearcher类)查询AD用户的msDS-User-Account-Control-Computed属性,不能使用Get-ADUser等AD模块cmdlet。但执行代码后返回值始终为0,且通过GetDirectoryEntry()无法获取该属性,即使设置SearchScope为Base也无效。该属性是构造属性,包含userAccountControl没有的标志(如LOCK_OUT、PASSWORD_EXPIRED),普通用户的预期值应与userAccountControl(512)一致或包含额外标志。
原因分析
msDS-User-Account-Control-Computed是动态构造属性,并非存储在AD数据库中的静态属性,而是由域控制器在查询时实时计算生成的:
- 这类属性必须在搜索时显式指定加载,否则域控制器不会返回;
- 默认的Subtree搜索作用域可能因LDAP优化策略,无法触发构造属性的计算逻辑;
GetDirectoryEntry()返回的是AD对象的绑定实例,仅包含持久化存储的属性,不会返回构造属性。
解决方案
使用Base作用域直接绑定到用户对象,显式请求该构造属性,确保域控制器正确计算并返回值。
正确代码示例
# 1. 查询当前用户的DistinguishedName $userSearcher = [adsisearcher] "(sAMAccountName=$env:USERNAME)" $userResult = $userSearcher.FindOne() $userDN = $userResult.Properties['distinguishedName'][0] # 2. 构造Base作用域查询,明确请求目标构造属性 $computedSearcher = [adsisearcher]::new() $computedSearcher.SearchRoot = "LDAP://$userDN" $computedSearcher.SearchScope = [System.DirectoryServices.SearchScope]::Base $computedSearcher.PropertiesToLoad.Add('msDS-User-Account-Control-Computed') | Out-Null # 3. 执行查询并获取结果 $computedResult = $computedSearcher.FindOne() $computedValue = $computedResult.Properties['msDS-User-Account-Control-Computed'][0] # 输出结果 Write-Host "msDS-User-Account-Control-Computed 值: $computedValue"
关键注意事项
- 确保属性名拼写准确:
msDS-User-Account-Control-Computed(LDAP属性名不区分大小写,但建议使用官方标准拼写); - Base作用域是触发构造属性计算的可靠方式,因为它直接针对单个对象请求;
- 不要通过
GetDirectoryEntry()获取该属性,构造属性仅会在LDAP搜索请求中返回; - 确认域功能级别至少为Windows Server 2003(该属性从该版本开始支持)。
内容的提问来源于stack exchange,提问作者stackprotector
相关产品推荐
相关产品推荐

