You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:通过PsExec批量推送Atera Agent MSI安装包失败问题

批量部署Atera Agent的脚本改进方案

原脚本的核心问题

  • 引号嵌套逻辑混乱,导致PsExec命令解析错误,这是批量执行失败的主要原因
  • 使用Invoke-Expression执行命令存在安全风险,且难以调试执行过程中的异常
  • 明文存储密码违反安全规范,易造成凭证泄露
  • 缺乏执行状态反馈和错误处理,无法定位单台机器的失败原因

改进后的脚本

# 配置参数
$computerListPath = "C:\Users\rvm\Desktop\pclist.txt"
$msiPath = "\\fs\Atera\setup.msi"
$username = "blah\blah"
$plainPassword = "blah" # 建议后续改用Get-Credential避免明文
$psexecPath = "psexec.exe" # 若PsExec不在PATH中,需指定完整路径如"C:\Tools\psexec.exe"

# 将明文密码转换为SecureString(可选,用于后续扩展)
$securePassword = ConvertTo-SecureString $plainPassword -AsPlainText -Force
$credential = New-Object System.Management.Automation.PSCredential ($username, $securePassword)

# 读取电脑列表
$computers = Get-Content $computerListPath

foreach ($computer in $computers) {
    Write-Host "正在处理电脑: $computer" -ForegroundColor Cyan

    # 先检查电脑是否在线
    if (-not (Test-Connection -ComputerName $computer -Count 1 -Quiet -ErrorAction SilentlyContinue)) {
        Write-Host "电脑 $computer 离线,跳过" -ForegroundColor Red
        continue
    }

    # 构建PsExec参数,避免引号嵌套问题
    $arguments = @(
        "\\$computer",
        "-u", $username,
        "-p", $plainPassword,
        "-h", # 以高权限运行
        "-s", # 可选:以系统账户运行,适合需要高权限的安装
        "msiexec.exe",
        "/i", "`"$msiPath`"",
        "/qn",
        "/norestart" # 避免强制重启,根据Atera Agent安装需求调整
    )

    try {
        # 启动PsExec进程并等待执行完成
        $process = Start-Process -FilePath $psexecPath -ArgumentList $arguments -Wait -NoNewWindow -PassThru -ErrorAction Stop
        
        if ($process.ExitCode -eq 0) {
            Write-Host "电脑 $computer 安装成功" -ForegroundColor Green
        } else {
            Write-Host "电脑 $computer 安装失败,退出代码: $($process.ExitCode)" -ForegroundColor Red
        }
    } catch {
        Write-Host "电脑 $computer 执行出错: $_" -ForegroundColor Red
    }
}

关键优化点说明

  • 使用Start-Process替代Invoke-Expression,直接传递参数数组,彻底避免引号嵌套错误
  • 添加在线检查,跳过离线机器,减少无效执行
  • 捕获执行异常并输出错误信息,便于排查问题
  • 保留-h参数确保高权限执行,可选添加-s以系统账户运行(部分Agent安装需要系统权限)
  • 添加/norestart参数防止安装强制重启用户电脑,可根据Atera官方文档调整

额外排查建议

  • 确保PsExec工具已加入系统PATH,或在脚本中指定完整路径
  • 验证共享文件夹\\fs\Atera的权限:确保指定的$username或远程电脑的系统账户有读取MSI文件的权限
  • 检查目标电脑防火墙:允许SMB(445端口)和PsExec临时端口的入站连接
  • 单台测试:先拿1-2台电脑测试改进后的脚本,确认正常后再批量执行
  • 密码安全:后续建议改用Get-Credential交互式输入密码,避免明文存储

内容的提问来源于stack exchange,提问作者WebsGhost

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 13:35:09