You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Atera自定义变量执行域加入脚本时遇访问拒绝错误求助

适配Atera变量的域加入脚本出现访问拒绝错误排查

问题背景

本地使用Read-Host获取凭据和OU信息的PowerShell脚本可正常将计算机加入域,但修改为适配Atera自定义脚本变量后,通过RMM执行时出现访问拒绝错误。

原本地可运行脚本

$domainName = "mydomain.live"

# Manually provide the username and password for joining the domain
$adminUsername = Read-Host "Enter the domain admin username"
$adminPassword = Read-Host -AsSecureString "Enter the domain admin password"

# Create a PSCredential object with the provided username and password
$credential = New-Object System.Management.Automation.PSCredential ($adminUsername, $adminPassword)

# Get the local computer name
$computerName = $env:COMPUTERNAME

# Prompt for the OU name where the computer should be added
$ouName = Read-Host "Enter the name of the parent Organizational Unit (OU)"
$childOUName = Read-Host "Enter the name of the child Organizational Unit (OU)"

# Join the computer to the domain and specify the target OU
Add-Computer -DomainName $domainName -Credential $credential -ComputerName $computerName -OUPath " OU=$childOUName,OU=$ouName, DC=mydomain, DC=live"  -Restart

修改后的Atera适配脚本

$domainName = 'mydomain.live'

# Manually provide the username and password for joining the domain
$adminUsername = [string]"{[adminUsername]}"
$adminPassword = [string]"{[adminPassword]}"

$encrypted = convertto-securestring $adminPassword -AsPlainText -Force

# Create a PSCredential object with the provided username and password
$credential = New-Object System.Management.Automation.PSCredential ($adminUsername, $encrypted)

# Get the local computer name
$computerName = $env:COMPUTERNAME

# Prompt for the OU name where the computer should be added
$ouName = [string]"{[ouName]}"
$childOUName = [string]"{[childOUName]}"

# Join the computer to the domain and specify the target OU
Add-Computer -DomainName $domainName -Credential $credential -ComputerName $computerName -OUPath "OU=$childOUName,OU=$ouName, DC=mydomain, DC=live"  -Restart

错误信息

Computer RH009 could not join domain MyDomain from WORKGROUP, access refused.
+ CategoryInfo          : OperationStopped: (MyDomain-RH009:String) [Add-Computer], InvalidOperationException
+ FullyQualifiedErrorId : FailToJoinDomainFromWorkgroup,Microsoft.PowerShell.Commands.AddComputerCommand

排查方向与解决建议

  • 验证凭据格式:确认Atera传入的$adminUsername包含完整域名前缀,比如mydomain\admin或admin@mydomain.live。本地手动输入时通常会带域名,但Atera变量可能遗漏,导致凭据无法被域控制器识别。
  • 检查密码处理:如果密码包含特殊字符(如!@#$%^&*),确认ConvertTo-SecureString是否正确解析。可在脚本中添加Write-Host "Encrypted Password Length: $($encrypted.Length)"验证密码是否正确转换。
  • 修正OU路径格式:LDAP路径中逗号后不能有空格,当前脚本的OUPath里DC=mydomain, DC=live存在多余空格,正确格式应为OU=$childOUName,OU=$ouName,DC=mydomain,DC=live(逗号后无空格)。格式错误会导致无法定位目标OU,触发权限验证失败。
  • 确认执行权限:Atera必须以本地管理员权限运行脚本。加域操作需要本地系统级权限,即使传入域管理员凭据,普通用户权限的进程也无法完成操作。在Atera脚本设置中勾选“以管理员身份运行”选项。
  • 验证变量替换:在脚本开头添加日志输出,比如:
    Write-Host "Admin Username: $adminUsername"
    Write-Host "OU Path: OU=$childOUName,OU=$ouName,DC=mydomain,DC=live"
    
    检查Atera是否正确替换了{[adminUsername]}等变量,避免因变量未替换导致凭据无效。
  • 排查域通信问题:确认目标机器能ping通域控制器,DNS服务器指向正确,且防火墙未阻止域加入所需端口(UDP 53、TCP 53、UDP 88、TCP 88、TCP 389、TCP 445等)。

内容的提问来源于stack exchange,提问作者Filip Godin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 02:52:47