如何用PowerShell获取所有用户配置文件的环境变量及类型
获取Windows 10所有用户及机器级环境变量的PowerShell实现
可以实现,Windows的环境变量本质存储在注册表中:机器级变量位于HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Environment,每个用户的用户级变量则存储在其配置文件的NTUSER.DAT对应的HKCU:\Environment键下。通过直接读取注册表并处理未登录用户的注册表 hive,可以获取所有用户的环境变量并区分类型。
以下是完整的PowerShell代码(需以管理员身份运行):
# -------------------------- # 1. 获取机器级环境变量 # -------------------------- $machineEnv = Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Environment' | Select-Object -Property * -ExcludeProperty PSPath, PSParentPath, PSChildName, PSDrive, PSProvider | Get-Member -MemberType NoteProperty | ForEach-Object { $propValue = (Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Environment').($_.Name) [PSCustomObject]@{ VariableName = $_.Name Value = $propValue Scope = '机器级' RegistryValueType = (Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Environment').PSObject.Properties[$_.Name].ValueKind } } # -------------------------- # 2. 获取所有本地用户的用户级环境变量 # -------------------------- $userEnvList = @() # 处理未登录的用户(需加载NTUSER.DAT) $unloadedUserProfiles = Get-CimInstance -ClassName Win32_UserProfile | Where-Object { $_.Special -eq $false -and $_.Loaded -ne $true } foreach ($profile in $unloadedUserProfiles) { $userSid = $profile.SID $ntuserDatPath = Join-Path -Path $profile.LocalPath -ChildPath 'NTUSER.DAT' if (Test-Path -Path $ntuserDatPath) { # 临时挂载用户注册表hive $mountPoint = "HKU:\$userSid" reg load $mountPoint $ntuserDatPath | Out-Null # 读取用户环境变量 $envKeyPath = "$mountPoint\Environment" if (Test-Path -Path $envKeyPath) { $userEnv = Get-ItemProperty -Path $envKeyPath | Select-Object -Property * -ExcludeProperty PSPath, PSParentPath, PSChildName, PSDrive, PSProvider | Get-Member -MemberType NoteProperty | ForEach-Object { $propValue = (Get-ItemProperty -Path $envKeyPath).($_.Name) [PSCustomObject]@{ VariableName = $_.Name Value = $propValue Scope = '用户级' RegistryValueType = (Get-ItemProperty -Path $envKeyPath).PSObject.Properties[$_.Name].ValueKind UserSID = $userSid UserProfilePath = $profile.LocalPath } } $userEnvList += $userEnv } # 卸载注册表hive,避免锁定NTUSER.DAT reg unload $mountPoint | Out-Null } } # 处理已登录的用户(注册表hive已加载) $loadedUserProfiles = Get-CimInstance -ClassName Win32_UserProfile | Where-Object { $_.Special -eq $false -and $_.Loaded -eq $true } foreach ($profile in $loadedUserProfiles) { $userSid = $profile.SID $envKeyPath = "HKU:\$userSid\Environment" if (Test-Path -Path $envKeyPath) { $userEnv = Get-ItemProperty -Path $envKeyPath | Select-Object -Property * -ExcludeProperty PSPath, PSParentPath, PSChildName, PSDrive, PSProvider | Get-Member -MemberType NoteProperty | ForEach-Object { $propValue = (Get-ItemProperty -Path $envKeyPath).($_.Name) [PSCustomObject]@{ VariableName = $_.Name Value = $propValue Scope = '用户级' RegistryValueType = (Get-ItemProperty -Path $envKeyPath).PSObject.Properties[$_.Name].ValueKind UserSID = $userSid UserProfilePath = $profile.LocalPath } } $userEnvList += $userEnv } } # -------------------------- # 3. 合并并输出结果 # -------------------------- $allEnvVariables = $machineEnv + $userEnvList # 控制台格式化输出 $allEnvVariables | Format-Table -AutoSize # 可选:导出到CSV文件 # $allEnvVariables | Export-Csv -Path 'AllEnvironmentVariables.csv' -Encoding UTF8 -NoTypeInformation
关键说明
- 权限要求:必须以管理员身份运行PowerShell,否则无法加载/卸载未登录用户的注册表hive。
- 变量类型区分:
Scope字段明确标记变量是机器级还是用户级;RegistryValueType字段显示注册表值类型(如REG_SZ为静态字符串、REG_EXPAND_SZ为可扩展的环境变量字符串)。 - 用户范围:默认排除了系统特殊用户配置文件(如Default、Public),如果需要包含这些,只需移除
Where-Object { $_.Special -eq $false }的过滤条件。 - 锁定问题:未登录用户处理完成后必须卸载注册表hive,否则其
NTUSER.DAT文件会被系统锁定,导致用户无法正常登录。
内容的提问来源于stack exchange,提问作者LightningJack
相关产品推荐
相关产品推荐

