PowerShell Get-ADUser因无效Win32 FileTime报错,如何排除日期属性?
解决Get-ADUser因无效FileTime报错的问题
问题背景
执行以下命令时,多数AD账号可正常返回信息:
Import-Module ActiveDirectory Get-ADUser <account> -Properties *
但部分账号会抛出如下错误:
Get-ADUser : Not a valid Win32 FileTime. Parameter name: fileTime At line:4 char:1 + Get-ADUser <account> -Properties AccountExpirationDate + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : InvalidArgument: (<account>:ADUser) [Get-ADUser], ArgumentOutOfRangeException + FullyQualifiedErrorId : ActiveDirectoryCmdlet:System.ArgumentOutOfRangeException,Microsoft.ActiveDirectory.Management.Commands.GetADUser
推测是AccountExpirationDate属性存在无效空值或异常时间格式导致,且不想逐个指定数百个属性来规避问题。
解决方案
错误发生在读取属性阶段,后续管道筛选无法生效,需提前排除出问题的属性。具体步骤如下:
- 先获取所有AD用户支持的属性列表,排除
AccountExpirationDate:
$allProperties = Get-ADUser -Filter * -Properties * | Get-Member -MemberType Property | Select-Object -ExpandProperty Name | Where-Object { $_ -ne 'AccountExpirationDate' }
- 使用筛选后的属性列表查询目标用户:
Get-ADUser <account> -Properties $allProperties
简化单行命令
Get-ADUser <account> -Properties (Get-ADUser -Filter * -Properties * | Get-Member -MemberType Property | Select-Object -ExpandProperty Name | Where-Object { $_ -ne 'AccountExpirationDate' })
补充说明
- 首次执行获取属性列表时会遍历所有用户,可能稍慢,后续复用该列表即可提升效率。
- 若还有其他类似日期属性报错,可按同样方法排除对应属性名称。
内容的提问来源于stack exchange,提问作者user23054840
相关产品推荐
相关产品推荐

