You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何移除Active Directory中用户的所有访问组成员身份(跨域场景)

解决跨域移除AD用户组成员时的"Referral was returned from the server"错误

问题根源

你遇到的错误是因为跨域操作AD组时未指定目标域的域控制器。当前代码默认使用用户所在域的DC(hostname.abc.def.com.au),但对于属于def.com.au域的组,该DC无法直接处理,需要指向该域的专用DC(hostname02.def.com.au)。

修复后的代码

# 获取待注销的用户名
$StoreName = Read-Host -Prompt 'Enter the Store name'
$ADStore = Get-ADUser -Identity $StoreName -Server hostname.abc.def.com.au -Properties MemberOf

# 遍历用户所属的所有组
foreach ($groupDN in $ADStore.MemberOf) {
    # 解析组的域信息(从组的DistinguishedName中提取域组件)
    $domainComponents = ($groupDN -split ',', 2)[1]
    $domainName = ($domainComponents -split 'DC=' | Where-Object { $_ }) -join '.'

    # 根据组的域选择对应的域控制器
    switch ($domainName) {
        'abc.def.com.au' { $dcServer = 'hostname.abc.def.com.au' }
        'def.com.au' { $dcServer = 'hostname02.def.com.au' }
        default { 
            Write-Warning "无法识别组 $groupDN 的域,跳过该组"
            continue
        }
    }

    # 执行移除组成员操作,指定对应域的DC
    try {
        Remove-ADGroupMember -Identity $groupDN -Members $ADStore.DistinguishedName -Server $dcServer -Confirm:$false -ErrorAction Stop
        Write-Host "已成功将用户从组 $groupDN 移除"
    }
    catch {
        Write-Error "移除组 $groupDN 时出错: $_"
    }
}

关键改进点

  • 解析组所属域:从组的DistinguishedName中提取域信息,确保每个组都匹配到正确的域控制器
  • 指定域控制器:针对不同域的组,调用Remove-ADGroupMember时显式传递-Server参数,避免跨域引用错误
  • 错误处理:添加try/catch块捕获异常,输出详细错误信息并跳过无法处理的组

内容的提问来源于stack exchange,提问作者Muhammad Usman Adil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 16:22:09