You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell通过CSV LocationID匹配AD用户departmentNumber报错求助

AD用户查询脚本报错排查

需求

根据给定的含重复LocationID的CSV列表,生成对应地点的AD用户报告,AD中用departmentNumber属性匹配LocationID。

编写的脚本

#Importing list of locations
$LocationData = Import-Csv "C:\Users\xxxx\xxxx\Desktop\LocationID.csv"
#Revising list of locations to only utilize single instances of each location
$LocationID = $LocationData | Select-Object LocationID -Unique
#Searching AD for each user that has a matching department to those held in $LocationID
Foreach ($Branch in $LocationID) {
$UserList = Get-ADUser -filter {departmentNumber -eq $($Branch.LocationID)} -Property * -SearchBase 'OU=xxxx,DC=xxxx,DC=xxxx,DC=xxxx' -server xxxxxxxx | Select-Object Name,Mail,Title,Manager,DepartmentNumber
}

运行报错信息

Get-ADUser : Cannot process argument because the value of argument "path" is not valid. Change the value of the "path" argument and run the operation again.
At line:3 char:13
+ $UserList = Get-ADUser -filter {departmentNumber -eq $($Branch.Locati ...
+             ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : NotSpecified: (:) [Get-ADUser], PSArgumentException
    + FullyQualifiedErrorId : ActiveDirectoryCmdlet:System.Management.Automation.PSArgumentException,Microsoft.ActiveDirectory.Management.Commands.GetADUser

错误原因及修正方案

错误核心原因

报错提示的path参数无效,对应脚本中-SearchBase指定的LDAP路径存在问题,主要可能是以下几种情况:

  • LDAP路径拼写错误:你填写的OU=xxxx,DC=xxxx,DC=xxxx,DC=xxxx路径不存在,比如OU名称大小写不匹配、DC段数量错误、符号写错(比如用了中文逗号),AD对LDAP路径的拼写要求严格,任何一处错误都会导致无法识别路径。
  • 权限不足:运行脚本的账号没有访问该目标OU的权限,导致AD无法返回该路径的有效信息。
  • 空LocationID干扰:如果CSV中存在空白的LocationID行,经过Select-Object -Unique后会产生空值,代入过滤器后可能导致AD查询解析异常(不过这个错误提示明确指向path,所以优先级低于前两个)。

修正步骤

  1. 验证并修正LDAP路径:
    运行以下命令获取所有OU的正确路径,复制目标OU的DistinguishedName替换到-SearchBase中:
    Get-ADOrganizationalUnit -Filter * | Select-Object DistinguishedName
    
  2. 检查账号权限:
    确保运行脚本的账号拥有目标OU的用户读取权限,必要时联系AD管理员调整权限。
  3. 过滤空LocationID:
    修改获取唯一LocationID的代码,提前过滤空值,避免无效查询:
    $LocationID = $LocationData | Where-Object { $_.LocationID -notmatch '^\s*$' } | Select-Object LocationID -Unique
    
  4. 修复用户列表覆盖问题:
    当前脚本中$UserList每次循环都会被覆盖,最终只会保留最后一个分支的用户数据。需要初始化空数组并追加数据:
    # 初始化空数组
    $UserList = @()
    Foreach ($Branch in $LocationID) {
        $UserList += Get-ADUser -filter {departmentNumber -eq $($Branch.LocationID)} -Property Name,Mail,Title,Manager,DepartmentNumber -SearchBase '正确的LDAP路径' -server xxxxxxxx
    }
    
    另外,-Property *会获取所有AD属性,建议只指定需要的属性(如上面的Name,Mail,Title,Manager,DepartmentNumber),提升查询效率。

内容的提问来源于stack exchange,提问作者Elijah Robinson

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 05:45:04