如何在.NET Core(C#)中获取AD内计算机的域加入者信息
通过C#(.NET Core)查找将计算机加入域的用户
原理说明
PowerShell方案的核心逻辑是读取Active Directory中计算机对象的nTSecurityDescriptor属性,提取其中的所有者信息。默认情况下,将计算机加入域的用户会成为该计算机AD对象的所有者,因此可以通过这个方式获取目标用户。
方案一:不依赖额外AD模块(对应PowerShell ADSI方案)
该方案使用System.DirectoryServices命名空间,无需安装额外AD模块,通过ADSI协议访问AD数据。
操作步骤
- 安装NuGet包:
System.DirectoryServices - 编写代码搜索目标计算机对象,读取其安全描述符并提取所有者
using System; using System.DirectoryServices; namespace ADComputerOwner { class Program { static void Main(string[] args) { string computerName = "myComputer"; // 替换为目标计算机名 string domainPath = "LDAP://DC=some,DC=domain,DC=com"; // 替换为你的域LDAP路径 // 创建AD搜索器 using (DirectorySearcher searcher = new DirectorySearcher(new DirectoryEntry(domainPath))) { searcher.Filter = $"(&(objectCategory=computer)(name={computerName}))"; searcher.PropertiesToLoad.Add("nTSecurityDescriptor"); // 指定加载安全描述符属性 SearchResult result = searcher.FindOne(); if (result != null) { // 获取安全描述符对象 ActiveDirectorySecurity securityDescriptor = result.GetDirectoryEntry().ObjectSecurity; // 获取所有者身份 IdentityReference owner = securityDescriptor.GetOwner(typeof(NTAccount)); Console.WriteLine($"将计算机加入域的用户:{owner.Value}"); } else { Console.WriteLine("未找到目标计算机对象"); } } } } }
方案二:贴合AD模块逻辑实现(对应PowerShell AD模块方案)
使用System.DirectoryServices.AccountManagement库,逻辑更贴近PowerShell的AD模块调用方式。
操作步骤
- 安装NuGet包:
System.DirectoryServices.AccountManagement - 编写代码获取计算机对象并读取安全描述符
using System; using System.DirectoryServices.AccountManagement; namespace ADComputerOwner { class Program { static void Main(string[] args) { string computerName = "myComputer"; string domainName = "some.domain.com"; using (PrincipalContext context = new PrincipalContext(ContextType.Domain, domainName)) { using (ComputerPrincipal computer = ComputerPrincipal.FindByIdentity(context, computerName)) { if (computer != null) { // 获取底层DirectoryEntry对象以读取nTSecurityDescriptor DirectoryEntry entry = computer.GetUnderlyingObject() as DirectoryEntry; entry.RefreshCache(new[] { "nTSecurityDescriptor" }); ActiveDirectorySecurity securityDescriptor = entry.ObjectSecurity; IdentityReference owner = securityDescriptor.GetOwner(typeof(NTAccount)); Console.WriteLine($"将计算机加入域的用户:{owner.Value}"); } else { Console.WriteLine("未找到目标计算机对象"); } } } } } }
注意事项
- 运行代码的账号需要具备读取Active Directory中计算机对象属性的权限
- 替换代码中的计算机名、域路径/域名为实际环境的值
- .NET Core环境下需确保安装对应NuGet包,不同版本包可能存在API差异
内容的提问来源于stack exchange,提问作者Ambrose Leung
相关产品推荐
相关产品推荐

