You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP调用PowerShell创建本地Exchange邮箱:访问拒绝问题求助

问题场景与错误信息

IIS 10服务器上的PHP程序调用PowerShell脚本创建用户邮箱,直接在Web服务器的PowerShell中运行该脚本正常,但通过PHP调用时提示访问拒绝,错误信息如下:

Connecting to remote server server.domain.local failed with the following error message : Access is denied. For more information, see the about_Remote_Troubleshooting Help topic. 
At C:\Scripts\AD_CreateMailbox.ps1:46 char:34 
+ ... sessionEX = New-PSSession -sessionOption $sessionOption -Configuratio ... 
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
+ CategoryInfo : OpenError: (System.Manageme....RemoteRunspace:RemoteRunspace) [New-PSSession], PSRemotingTransportException 
+ FullyQualifiedErrorId : AccessDenied,PSSessionOpenFailed

已执行的操作:

  • 在Exchange服务器上启用Remote Powershell
  • 在Exchange的WinRM可信主机中添加Web服务器
  • 使用具备创建邮箱权限的受限域用户运行Web服务器
  • 在Exchange服务器上启用Kerberos认证
解决建议

一、配置IIS身份模拟(核心步骤)

  1. 打开IIS管理器,定位到目标网站对应的应用程序池
  2. 右键点击应用程序池,选择「高级设置」,在「进程模型」下的「标识」项,确认已设置为你指定的具备Exchange权限的受限域用户(若未设置,点击「...」按钮选择该域用户)
  3. 返回目标网站/应用程序,双击「身份验证」模块
  4. 找到「匿名身份验证」,右键选择「编辑」,选择「应用程序池标识」(或直接指定该域用户),点击确定
  5. 启用「ASP.NET模拟」:双击「ASP.NET模拟」,点击「启用」,再点击「编辑」,选择「应用程序池标识」(或指定该域用户),保存设置
  6. 重启应用程序池和网站,使配置生效

二、补充权限与配置排查

  • Exchange权限确认:确保该域用户被分配了Exchange的「Mail Recipient Creation」角色(可通过Exchange管理中心或PowerShell命令Add-RoleGroupMember "Mail Recipient Creation" -Member "域用户名"配置),同时添加到Exchange服务器的「Remote Management Users」本地组
  • Web服务器PowerShell执行策略:以管理员身份打开PowerShell,执行Set-ExecutionPolicy RemoteSigned,允许本地脚本正常运行
  • WinRM连接测试:在Web服务器上,用该域用户身份运行Test-WSMan server.domain.local,验证Kerberos连接是否正常,若报错需排查域信任或SPN配置
  • PHP执行上下文检查:在PHP代码中执行exec("whoami"),输出当前执行用户,确认是否为指定的域用户
  • Exchange远程PS权限验证:在Exchange服务器上执行Get-User "域用户名" | Select-Object RemotePowerShellEnabled,确认RemotePowerShellEnabled属性为True

内容的提问来源于stack exchange,提问作者Ben74

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 05:41:17