You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将AD门店OU列表转为选择菜单,实现单门店用户密码重置

实现按门店OU选择重置AD用户密码的PowerShell脚本

以下是完整的可运行脚本,整合了OU选择菜单、输入验证、精准用户筛选及密码重置逻辑,彻底避免全公司批量操作的风险:

# 获取所有以store-开头的一级OU
$storeOUs = Get-ADOrganizationalUnit -Filter 'Name -like "store-*"' -Properties Name, DistinguishedName | Sort-Object Name

# 检查是否有符合条件的OU
if (-not $storeOUs) {
    Write-Host "未找到以store-开头的门店OU,请检查筛选条件。" -ForegroundColor Red
    exit
}

# 显示带编号的选择菜单
Write-Host "=== 门店OU选择菜单 ===" -ForegroundColor Cyan
for ($i = 0; $i -lt $storeOUs.Count; $i++) {
    Write-Host "$($i+1). $($storeOUs[$i].Name) - $($storeOUs[$i].DistinguishedName)"
}

# 获取并验证用户输入
do {
    $selection = Read-Host "请输入目标门店的编号(1-$($storeOUs.Count))"
    if ($selection -match '^\d+$') {
        $selectedIndex = [int]$selection - 1
        $validInput = ($selectedIndex -ge 0) -and ($selectedIndex -lt $storeOUs.Count)
    } else {
        $validInput = $false
    }
    if (-not $validInput) {
        Write-Host "输入无效,请输入1到$($storeOUs.Count)之间的数字。" -ForegroundColor Yellow
    }
} while (-not $validInput)

$selectedOU = $storeOUs[$selectedIndex]
Write-Host "已选择门店:$($selectedOU.Name)" -ForegroundColor Green

# 定义密码过期天数
$days = 42  # 根据GPO设置调整

# 筛选选中OU下符合条件的启用用户(pwdLastSet超过指定天数)
$users = Get-ADUser -Filter { Enabled -eq $true } `
    -SearchBase $selectedOU.DistinguishedName `
    -Properties pwdLastSet, DistinguishedName |
    Select-Object SamAccountName, DistinguishedName, @{n='pwdLastSet'; e={[DateTime]::FromFileTime($_.pwdLastSet)}} |
    Where-Object { $_.pwdLastSet -lt (Get-Date).AddDays(-$days) }

# 检查是否有需要处理的用户
if (-not $users) {
    Write-Host "该门店下没有符合条件(密码最后设置超过$days天)的启用用户。" -ForegroundColor Cyan
    exit
}

# 显示待处理用户信息并确认操作
Write-Host "`n即将重置以下$($users.Count)个用户的密码:" -ForegroundColor Yellow
$users | Format-Table SamAccountName, pwdLastSet, DistinguishedName -AutoSize

$confirm = Read-Host "确认执行密码重置操作吗?(Y/N)"
if ($confirm -notmatch '^[Yy]$') {
    Write-Host "操作已取消。" -ForegroundColor Cyan
    exit
}

# 执行密码重置逻辑
foreach ($user in $users) {
    try {
        $adUser = Get-ADUser $user.SamAccountName -Properties pwdLastSet
        # 重置pwdLastSet为0(强制下次登录改密码)
        $adUser.pwdLastSet = 0
        Set-ADUser -Instance $adUser -ErrorAction Stop
        # 重置为-1(更新pwdLastSet为当前时间)
        $adUser.pwdLastSet = -1
        Set-ADUser -Instance $adUser -ErrorAction Stop
        Write-Host "成功重置用户:$($user.SamAccountName)" -ForegroundColor Green
    } catch {
        Write-Host "重置用户$($user.SamAccountName)失败:$($_.Exception.Message)" -ForegroundColor Red
    }
}

Write-Host "`n密码重置操作完成。" -ForegroundColor Cyan

核心功能说明

1. 门店OU菜单生成

  • 自动筛选并展示所有store-开头的OU,按名称排序后添加编号,方便管理员快速定位目标门店
  • 无符合条件OU时直接终止脚本,避免无效操作

2. 输入合法性验证

  • 强制要求输入数字编号,且范围限定在菜单有效区间内,非法输入会循环提示重新输入

3. 精准用户范围控制

  • 通过-SearchBase参数锁定选中的门店OU,仅处理该OU下的用户,从根源杜绝全公司批量操作的风险
  • 保留原需求的筛选条件:仅针对启用状态、密码最后设置时间超过指定天数的用户

4. 安全操作确认

  • 执行重置前展示待处理用户列表,要求管理员手动确认后再执行,降低误操作概率
  • 加入异常捕获机制,单个用户重置失败不会中断整个脚本,同时输出错误信息便于排查

5. 逻辑优化

  • 减少AD服务器查询次数,筛选用户时一次性获取所需属性
  • 为每个用户的重置结果添加状态提示,清晰反馈操作进度

内容的提问来源于stack exchange,提问作者user23392693

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 02:05:32