低权限PowerShell脚本中以管理员身份执行DHCP IP预留查询的故障排查求助
Hey there! Let's work through the issues you're facing with running that DHCP query as an admin from your non-admin PowerShell script. Here are the key problems and fixes to try:
1. Your dhcp Function Isn't Available to the Job Session
When you use Start-Job, it spins up a completely separate PowerShell session. Right now, you're defining the dhcp function after calling Start-Job, so the job session never sees the function definition. You need to either:
Option A: Define the function before starting the job
# Define the function first function dhcp { param($mac) $result = Get-DhcpServerv4Lease -ComputerName xxx.xxx.xxx.xxx -ScopeId xxx.xxx.xxx.xxx | findstr $mac # Ensure C:\temp exists first to avoid write errors if (-not (Test-Path C:\temp)) { New-Item -ItemType Directory -Path C:\temp | Out-Null } $result | Out-File -FilePath C:\temp\result.txt } # Now start the job with credentials and pass the MAC variable Start-Job -Credential $Credentials -ScriptBlock ${function:dhcp} -ArgumentList $mac
Option B: Embed the function logic directly in the ScriptBlock
This avoids relying on the parent session's function definitions entirely:
$mac = "your-target-mac-address" Start-Job -Credential $Credentials -ScriptBlock { param($mac) $result = Get-DhcpServerv4Lease -ComputerName xxx.xxx.xxx.xxx -ScopeId xxx.xxx.xxx.xxx | findstr $mac if (-not (Test-Path C:\temp)) { New-Item -ItemType Directory -Path C:\temp | Out-Null } $result | Out-File -FilePath C:\temp\result.txt } -ArgumentList $mac
2. The $mac Variable Isn't Passed to the Job Session
Your original code uses @mac but doesn't pass the variable into the job's isolated session. The -ArgumentList parameter lets you send variables from your main session into the job (as shown in the examples above).
3. Check for Job Errors (They Don't Show Up Automatically!)
Background jobs don't surface errors in your main console by default. To diagnose what's failing, run these commands after starting the job:
# Get all active jobs and their status Get-Job # Retrieve job output and error details Get-Job | Receive-Job -ErrorAction Stop Get-Job | Format-List * # Shows full job details including error messages
This will tell you if there's a permissions issue writing to C:\temp, if the DHCP server is unreachable, or if there's a syntax error in your script block.
4. Alternative: Use Start-Process Instead of Start-Job
If you don't need a background job, running the DHCP command directly in an elevated PowerShell process might be simpler:
$mac = "your-target-mac-address" $command = @" `$result = Get-DhcpServerv4Lease -ComputerName xxx.xxx.xxx.xxx -ScopeId xxx.xxx.xxx.xxx | findstr "$mac" if (-not (Test-Path C:\temp)) { New-Item -ItemType Directory -Path C:\temp | Out-Null } `$result | Out-File -FilePath C:\temp\result.txt "@ Start-Process powershell.exe -Credential $Credentials -ArgumentList "-NoProfile -Command $command" -Wait
The -Wait flag ensures your main script waits for the elevated process to finish before continuing.
5. Avoid findstr in PowerShell (Use Native Cmdlets Instead)
While findstr works, PowerShell's native Where-Object is more reliable and integrates better with DHCP lease objects. Here's a cleaner way to filter for your MAC address:
$result = Get-DhcpServerv4Lease -ComputerName xxx.xxx.xxx.xxx -ScopeId xxx.xxx.xxx.xxx | Where-Object { $_.PhysicalAddress -eq $mac -or $_.ClientId -eq $mac }
This checks both common fields where MAC addresses are stored in DHCP leases.
内容的提问来源于stack exchange,提问作者Lin4th

