You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

修改PowerShell脚本导出AD安全组管理者的SamAccountName与attribute09

解决方案

修改后的脚本会导出安全组名称、管理员的DistinguishedName、SamAccountName以及员工ID(attribute09),代码如下:

$Groups = Get-Content C:\Scripts\Groups.txt
$Groups | ForEach-Object {
    # 获取安全组及其ManagedBy属性
    $group = Get-ADGroup -Identity $_ -Properties ManagedBy
    if ($group.ManagedBy) {
        # 查询管理员用户的指定属性
        $manager = Get-ADUser -Identity $group.ManagedBy -Properties SamAccountName, attribute09
        # 构造自定义导出对象
        [PSCustomObject]@{
            GroupName               = $group.Name
            ManagerDistinguishedName = $group.ManagedBy
            ManagerSamAccountName   = $manager.SamAccountName
            EmployeeID              = $manager.attribute09
        }
    } else {
        # 处理无管理员的安全组
        [PSCustomObject]@{
            GroupName               = $group.Name
            ManagerDistinguishedName = $null
            ManagerSamAccountName   = $null
            EmployeeID              = $null
        }
    }
} | Export-CSV Groups.csv -NoTypeInformation -Encoding UTF8

关键修改说明

  • 先将组对象存储到$group变量,避免重复查询AD
  • 增加ManagedBy非空判断,防止无管理员的组触发查询错误
  • 通过Get-ADUser明确获取管理员的SamAccountName和attribute09属性(如果AD中实际扩展属性是extensionAttribute09,请替换为对应名称)
  • 用[PSCustomObject]自定义输出字段,确保CSV包含所有需要的信息
  • 添加-Encoding UTF8参数,避免导出CSV时出现中文乱码问题

内容的提问来源于stack exchange,提问作者j-mo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 08:03:18