PowerShell通过CSV LocationID匹配AD用户departmentNumber报错求助
AD用户查询脚本报错排查
需求
根据给定的含重复LocationID的CSV列表,生成对应地点的AD用户报告,AD中用departmentNumber属性匹配LocationID。
编写的脚本
#Importing list of locations $LocationData = Import-Csv "C:\Users\xxxx\xxxx\Desktop\LocationID.csv" #Revising list of locations to only utilize single instances of each location $LocationID = $LocationData | Select-Object LocationID -Unique #Searching AD for each user that has a matching department to those held in $LocationID Foreach ($Branch in $LocationID) { $UserList = Get-ADUser -filter {departmentNumber -eq $($Branch.LocationID)} -Property * -SearchBase 'OU=xxxx,DC=xxxx,DC=xxxx,DC=xxxx' -server xxxxxxxx | Select-Object Name,Mail,Title,Manager,DepartmentNumber }
运行报错信息
Get-ADUser : Cannot process argument because the value of argument "path" is not valid. Change the value of the "path" argument and run the operation again. At line:3 char:13 + $UserList = Get-ADUser -filter {departmentNumber -eq $($Branch.Locati ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : NotSpecified: (:) [Get-ADUser], PSArgumentException + FullyQualifiedErrorId : ActiveDirectoryCmdlet:System.Management.Automation.PSArgumentException,Microsoft.ActiveDirectory.Management.Commands.GetADUser
错误原因及修正方案
错误核心原因
报错提示的path参数无效,对应脚本中-SearchBase指定的LDAP路径存在问题,主要可能是以下几种情况:
- LDAP路径拼写错误:你填写的
OU=xxxx,DC=xxxx,DC=xxxx,DC=xxxx路径不存在,比如OU名称大小写不匹配、DC段数量错误、符号写错(比如用了中文逗号),AD对LDAP路径的拼写要求严格,任何一处错误都会导致无法识别路径。 - 权限不足:运行脚本的账号没有访问该目标OU的权限,导致AD无法返回该路径的有效信息。
- 空LocationID干扰:如果CSV中存在空白的LocationID行,经过
Select-Object -Unique后会产生空值,代入过滤器后可能导致AD查询解析异常(不过这个错误提示明确指向path,所以优先级低于前两个)。
修正步骤
- 验证并修正LDAP路径:
运行以下命令获取所有OU的正确路径,复制目标OU的DistinguishedName替换到-SearchBase中:Get-ADOrganizationalUnit -Filter * | Select-Object DistinguishedName - 检查账号权限:
确保运行脚本的账号拥有目标OU的用户读取权限,必要时联系AD管理员调整权限。 - 过滤空LocationID:
修改获取唯一LocationID的代码,提前过滤空值,避免无效查询:$LocationID = $LocationData | Where-Object { $_.LocationID -notmatch '^\s*$' } | Select-Object LocationID -Unique - 修复用户列表覆盖问题:
当前脚本中$UserList每次循环都会被覆盖,最终只会保留最后一个分支的用户数据。需要初始化空数组并追加数据:
另外,# 初始化空数组 $UserList = @() Foreach ($Branch in $LocationID) { $UserList += Get-ADUser -filter {departmentNumber -eq $($Branch.LocationID)} -Property Name,Mail,Title,Manager,DepartmentNumber -SearchBase '正确的LDAP路径' -server xxxxxxxx }-Property *会获取所有AD属性,建议只指定需要的属性(如上面的Name,Mail,Title,Manager,DepartmentNumber),提升查询效率。
内容的提问来源于stack exchange,提问作者Elijah Robinson
相关产品推荐
相关产品推荐

