为何无法通过CSV将用户添加至OU?PowerShell脚本报错求助
使用PowerShell从CSV创建AD用户时出现"服务器不愿处理请求"错误
错误信息
New-ADUser : The server is unwilling to process the request At C:\CreateADUsersFromCSV_expanded.ps1:19 char:1 + New-ADUser ` + ~~~~ + CategoryInfo : NotSpecified: (CN=Mike Terry,O...racademy,DC=com :String) [New-ADUser], ADException + FullyQualifiedErrorId : ActiveDirectoryServer:0,Microsoft.ActiveDirector y.Management.Commands.NewADUser
脚本内容
# Import the AD Module Import-Module ActiveDirectory $filepath = Read-Host -Prompt "Please enter the path to the CSV file that contains the new user accounts" $users = Import-CSV $filepath ForEach ($user in $users) { New-ADUser ` -Name ($user.'First Name' + " " + $user.'Last Name') ` -GivenName $user.'First Name' ` -Surname $user.'Last Name' ` -UserPrincipalName ($user.'First Name' + "." + $user.'Last Name') ` -AccountPassword (ConvertTo-SecureString "P@$$w0rd123" -AsPlainText -Force) ` -Description $user.Description ` -EmailAddress $user.'Email Address' ` -Title $user.'Job Title' ` -OfficePhone $user.'Office Phone' ` -Path $user.'Organizational Unit' ` }
问题定位
错误指向-Path $user.'Organizational Unit'参数,核心原因是CSV中填写的OU格式不符合AD要求:
- AD的
-Path参数需要完整的LDAP区分名(DN),比如OU=销售部,DC=company,DC=com,而不是仅填写OU的显示名称(如"销售部")。 - 如果CSV中的OU路径不完整、拼写错误,或者目标OU不存在,都会触发这个错误。
解决方法
修正CSV的OU路径
将Organizational Unit列的值改为目标OU的完整LDAP区分名。可以通过以下方式获取:- 在ADUC中右键目标OU → 属性 → 编辑器 → 找到
distinguishedName属性,复制其值。 - 用PowerShell命令查询:
Get-ADOrganizationalUnit -Filter "Name -eq '目标OU名称'" | Select-Object DistinguishedName
- 在ADUC中右键目标OU → 属性 → 编辑器 → 找到
增加OU有效性校验
在脚本中添加检查逻辑,避免因OU不存在导致创建失败:Import-Module ActiveDirectory $filepath = Read-Host -Prompt "请输入包含新用户账号的CSV文件路径" $users = Import-CSV $filepath ForEach ($user in $users) { # 检查目标OU是否存在 $targetOU = $user.'Organizational Unit' if (-not (Get-ADOrganizationalUnit -Filter "DistinguishedName -eq '$targetOU'" -ErrorAction SilentlyContinue)) { Write-Warning "OU [$targetOU] 不存在,跳过用户 $($user.'First Name') $($user.'Last Name')" continue } # 创建AD用户 New-ADUser ` -Name ($user.'First Name' + " " + $user.'Last Name') ` -GivenName $user.'First Name' ` -Surname $user.'Last Name' ` -UserPrincipalName ($user.'First Name' + "." + $user.'Last Name') ` -AccountPassword (ConvertTo-SecureString "P@$$w0rd123" -AsPlainText -Force) ` -Description $user.Description ` -EmailAddress $user.'Email Address' ` -Title $user.'Job Title' ` -OfficePhone $user.'Office Phone' ` -Path $targetOU ` -Enabled $true # 可选:默认创建的用户是禁用状态,添加此参数启用账号 }其他排查方向
- 确认运行脚本的账号拥有目标OU下创建用户的权限。
- 检查硬编码密码
P@$$w0rd123是否符合域密码策略(长度、复杂度、历史要求等)。
内容的提问来源于stack exchange,提问作者chkontog
相关产品推荐
相关产品推荐

