You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell技术问题:为何-Properties *无法列出全部属性及隐藏属性获取方法

PowerShell Get-ADUser 属性获取常见问题

Q1. 为何使用-Properties *参数无法列出对象的所有属性?

-Properties *在Get-ADUser中仅会返回AD架构里标记为「默认返回」或「可选返回」的常规属性,但像msDS-UserPasswordExpiryTimeComputed这类**构造属性(constructed attribute)**不在*的覆盖范围内。这类属性是AD在查询时动态计算生成的,不属于AD对象存储的固有属性集合,因此通配符无法匹配到它们。

Q2. 如何列出对象的所有隐藏属性(包括构造属性)?

要获取包含构造属性在内的所有属性,可通过以下两种方式实现:

  • 明确指定构造属性:将目标构造属性名称与*组合,加入-Properties参数,示例:-Properties *,msDS-UserPasswordExpiryTimeComputed,既保留所有常规属性,又添加需要的构造属性。
  • 批量查询构造属性列表:先从AD架构中找出所有构造属性,再按需指定。执行以下命令获取所有构造属性的名称:
Get-ADObject -SearchBase (Get-ADRootDSE).schemaNamingContext -Filter {objectClass -eq 'attributeSchema' -and isConstructed -eq $true} -Properties lDAPDisplayName | Select-Object lDAPDisplayName

示例1:属性数量对比

$u = "myUsername"
(Get-ADUser $u -Properties *                                     | Get-Member | Measure-Object).Count
(Get-ADUser $u -Properties *,msDS-UserPasswordExpiryTimeComputed | Get-Member | Measure-Object).Count

#输出:
#211
#212

使用-Properties *仅返回211个属性,明确添加构造属性后数量增加到212,说明构造属性未被通配符覆盖。

示例2:缺失的属性

Get-ADUser $u -Properties * | Select msDS-UserPasswordExpiryTimeComputed
Get-ADUser $u -Properties *,msDS-UserPasswordExpiryTimeComputed  | Select msDS-UserPasswordExpiryTimeComputed

#输出:
#msDS-UserPasswordExpiryTimeComputed
#-----------------------------------
#                                   
#133330391314691704  

仅用-Properties *时,构造属性无有效返回值;明确指定后,成功获取到AD动态计算的密码过期时间戳。


内容的提问来源于stack exchange,提问作者Steven

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 03:27:26