PHP调用PowerShell创建本地Exchange邮箱:访问拒绝问题求助
问题场景与错误信息
IIS 10服务器上的PHP程序调用PowerShell脚本创建用户邮箱,直接在Web服务器的PowerShell中运行该脚本正常,但通过PHP调用时提示访问拒绝,错误信息如下:
Connecting to remote server server.domain.local failed with the following error message : Access is denied. For more information, see the about_Remote_Troubleshooting Help topic. At C:\Scripts\AD_CreateMailbox.ps1:46 char:34 + ... sessionEX = New-PSSession -sessionOption $sessionOption -Configuratio ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : OpenError: (System.Manageme....RemoteRunspace:RemoteRunspace) [New-PSSession], PSRemotingTransportException + FullyQualifiedErrorId : AccessDenied,PSSessionOpenFailed
已执行的操作:
- 在Exchange服务器上启用Remote Powershell
- 在Exchange的WinRM可信主机中添加Web服务器
- 使用具备创建邮箱权限的受限域用户运行Web服务器
- 在Exchange服务器上启用Kerberos认证
解决建议
一、配置IIS身份模拟(核心步骤)
- 打开IIS管理器,定位到目标网站对应的应用程序池
- 右键点击应用程序池,选择「高级设置」,在「进程模型」下的「标识」项,确认已设置为你指定的具备Exchange权限的受限域用户(若未设置,点击「...」按钮选择该域用户)
- 返回目标网站/应用程序,双击「身份验证」模块
- 找到「匿名身份验证」,右键选择「编辑」,选择「应用程序池标识」(或直接指定该域用户),点击确定
- 启用「ASP.NET模拟」:双击「ASP.NET模拟」,点击「启用」,再点击「编辑」,选择「应用程序池标识」(或指定该域用户),保存设置
- 重启应用程序池和网站,使配置生效
二、补充权限与配置排查
- Exchange权限确认:确保该域用户被分配了Exchange的「Mail Recipient Creation」角色(可通过Exchange管理中心或PowerShell命令
Add-RoleGroupMember "Mail Recipient Creation" -Member "域用户名"配置),同时添加到Exchange服务器的「Remote Management Users」本地组 - Web服务器PowerShell执行策略:以管理员身份打开PowerShell,执行
Set-ExecutionPolicy RemoteSigned,允许本地脚本正常运行 - WinRM连接测试:在Web服务器上,用该域用户身份运行
Test-WSMan server.domain.local,验证Kerberos连接是否正常,若报错需排查域信任或SPN配置 - PHP执行上下文检查:在PHP代码中执行
exec("whoami"),输出当前执行用户,确认是否为指定的域用户 - Exchange远程PS权限验证:在Exchange服务器上执行
Get-User "域用户名" | Select-Object RemotePowerShellEnabled,确认RemotePowerShellEnabled属性为True
内容的提问来源于stack exchange,提问作者Ben74
相关产品推荐
相关产品推荐

