You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在PowerShell中通过SID获取/创建WindowsIdentity对象

通过SID获取WindowsIdentity对象的解决方案

在PowerShell中,直接使用SecurityIdentifier对象实例化WindowsIdentity时会抛出"The name provided is not a properly formed account name."错误,这是因为该构造函数对SID的解析存在限制。以下是两种可行的解决方法:

方法一:先将SID转换为NTAccount账户名

先把SID字符串解析为SecurityIdentifier对象,再转换为对应的NTAccount获取完整账户名称(格式通常为域\用户名),最后用该名称创建WindowsIdentity:

# 替换为目标SID字符串
$sidString = 'S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-1001'

# 转换为SecurityIdentifier对象
$sid = [System.Security.Principal.SecurityIdentifier]$sidString

# 转换为NTAccount以获取完整账户名
$ntAccount = $sid.Translate([System.Security.Principal.NTAccount])

# 通过账户名实例化WindowsIdentity
$windowsIdentity = New-Object System.Security.Principal.WindowsIdentity($ntAccount.Value)

方法二:使用SID的二进制数据构造

直接提取SID的二进制形式,传入WindowsIdentity的字节数组构造函数,无需解析账户名:

# 替换为目标SID字符串
$sidString = 'S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-1001'

$sid = [System.Security.Principal.SecurityIdentifier]$sidString
# 初始化存储SID二进制数据的数组
$sidBytes = New-Object byte[] $sid.BinaryLength
# 将SID转换为二进制形式
$sid.GetBinaryForm($sidBytes, 0)

# 通过二进制数据实例化WindowsIdentity
$windowsIdentity = New-Object System.Security.Principal.WindowsIdentity($sidBytes)

两种方法都能成功创建目标用户的WindowsIdentity对象,可根据场景选择使用。

内容的提问来源于stack exchange,提问作者Dennis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 01:49:53