You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Python(ldap3)通过Windows登录凭证访问Active Directory

无需手动输入账号密码,用当前Windows登录用户凭证连接AD的解决方案

可以直接使用当前Windows登录用户的凭证访问AD,不需要手动输入账号密码。ldap3在Windows环境下支持通过**SSPI(Security Support Provider Interface)**自动获取当前用户的认证凭证,无需额外依赖Win32库。

替换后的连接代码

from ldap3 import Server, Connection, AUTH_SSPI

try:
    # 初始化AD服务器实例
    server = Server(ad_server, get_info='ALL')
    # 使用SSPI认证,自动复用当前Windows登录用户的凭证
    conn = Connection(server, authentication=AUTH_SSPI, auto_bind=True)
    print("Connected using current Windows credentials!")
    return conn
except Exception as e:
    print("Error:", e)
    return None

关键说明

  • AUTH_SSPI认证方式:ldap3封装了Windows系统的SSPI接口,会自动调用当前登录用户的Kerberos或NTLM凭证完成AD认证,无需手动传入user和password参数。
  • 权限要求:当前Windows登录用户必须拥有AD中执行账号创建操作的权限(例如属于Account Operators组,或被分配了目标OU的用户创建权限),否则会返回权限不足的错误。
  • 环境要求:运行代码的机器需加入AD域,或当前登录用户为域用户(本地用户通常无法通过SSPI访问域环境的AD)。

内容的提问来源于stack exchange,提问作者Mateusz Kowalski

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 13:08:18