使用Atera自定义变量执行域加入脚本时遇访问拒绝错误求助
适配Atera变量的域加入脚本出现访问拒绝错误排查
问题背景
本地使用Read-Host获取凭据和OU信息的PowerShell脚本可正常将计算机加入域,但修改为适配Atera自定义脚本变量后,通过RMM执行时出现访问拒绝错误。
原本地可运行脚本
$domainName = "mydomain.live" # Manually provide the username and password for joining the domain $adminUsername = Read-Host "Enter the domain admin username" $adminPassword = Read-Host -AsSecureString "Enter the domain admin password" # Create a PSCredential object with the provided username and password $credential = New-Object System.Management.Automation.PSCredential ($adminUsername, $adminPassword) # Get the local computer name $computerName = $env:COMPUTERNAME # Prompt for the OU name where the computer should be added $ouName = Read-Host "Enter the name of the parent Organizational Unit (OU)" $childOUName = Read-Host "Enter the name of the child Organizational Unit (OU)" # Join the computer to the domain and specify the target OU Add-Computer -DomainName $domainName -Credential $credential -ComputerName $computerName -OUPath " OU=$childOUName,OU=$ouName, DC=mydomain, DC=live" -Restart
修改后的Atera适配脚本
$domainName = 'mydomain.live' # Manually provide the username and password for joining the domain $adminUsername = [string]"{[adminUsername]}" $adminPassword = [string]"{[adminPassword]}" $encrypted = convertto-securestring $adminPassword -AsPlainText -Force # Create a PSCredential object with the provided username and password $credential = New-Object System.Management.Automation.PSCredential ($adminUsername, $encrypted) # Get the local computer name $computerName = $env:COMPUTERNAME # Prompt for the OU name where the computer should be added $ouName = [string]"{[ouName]}" $childOUName = [string]"{[childOUName]}" # Join the computer to the domain and specify the target OU Add-Computer -DomainName $domainName -Credential $credential -ComputerName $computerName -OUPath "OU=$childOUName,OU=$ouName, DC=mydomain, DC=live" -Restart
错误信息
Computer RH009 could not join domain MyDomain from WORKGROUP, access refused. + CategoryInfo : OperationStopped: (MyDomain-RH009:String) [Add-Computer], InvalidOperationException + FullyQualifiedErrorId : FailToJoinDomainFromWorkgroup,Microsoft.PowerShell.Commands.AddComputerCommand
排查方向与解决建议
- 验证凭据格式:确认Atera传入的
$adminUsername包含完整域名前缀,比如mydomain\admin或admin@mydomain.live。本地手动输入时通常会带域名,但Atera变量可能遗漏,导致凭据无法被域控制器识别。 - 检查密码处理:如果密码包含特殊字符(如
!@#$%^&*),确认ConvertTo-SecureString是否正确解析。可在脚本中添加Write-Host "Encrypted Password Length: $($encrypted.Length)"验证密码是否正确转换。 - 修正OU路径格式:LDAP路径中逗号后不能有空格,当前脚本的
OUPath里DC=mydomain, DC=live存在多余空格,正确格式应为OU=$childOUName,OU=$ouName,DC=mydomain,DC=live(逗号后无空格)。格式错误会导致无法定位目标OU,触发权限验证失败。 - 确认执行权限:Atera必须以本地管理员权限运行脚本。加域操作需要本地系统级权限,即使传入域管理员凭据,普通用户权限的进程也无法完成操作。在Atera脚本设置中勾选“以管理员身份运行”选项。
- 验证变量替换:在脚本开头添加日志输出,比如:
检查Atera是否正确替换了Write-Host "Admin Username: $adminUsername" Write-Host "OU Path: OU=$childOUName,OU=$ouName,DC=mydomain,DC=live"{[adminUsername]}等变量,避免因变量未替换导致凭据无效。 - 排查域通信问题:确认目标机器能ping通域控制器,DNS服务器指向正确,且防火墙未阻止域加入所需端口(UDP 53、TCP 53、UDP 88、TCP 88、TCP 389、TCP 445等)。
内容的提问来源于stack exchange,提问作者Filip Godin
相关产品推荐
相关产品推荐

