You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell禁用90天未活动AD用户脚本报错求助

解决禁用90天未活动AD用户的PowerShell脚本错误

问题描述

编写了用于禁用90天以上未活动AD用户的PowerShell脚本,但执行时出现以下错误:

Disable-ADAccount : Cannot bind parameter 'Identity'. Cannot create object of type "Microsoft.ActiveDirectory.Management.ADAccount". The adapter cannot set the value of property "Name".

虽然echo $DisabledUsers能正确显示用户信息,但Disable-ADAccount无法识别筛选出的对象。

需要满足的检查条件:

核心条件

  • PasswordLastSet属性早于90天
  • LastLogonTimestamp属性早于90天

额外条件

  • 账号处于启用状态
  • 未设置密码永不过期属性
  • LastLogonDate属性不为空
  • LastLogonDate属性未设为1/1/1601
  • 账号创建时间不早于90天

错误原因

脚本中使用Select-Object仅提取了部分属性,返回的是自定义PSObject对象,而非Microsoft.ActiveDirectory.Management.ADUser对象。Disable-ADAccount需要接收ADUser对象或可直接识别的标识(如SamAccountName),因此无法绑定参数。

修正后的脚本

方案1:保留原始ADUser对象(推荐)

先筛选出符合条件的ADUser对象,再输出需要的信息,最后循环禁用:

$main_date = [DateTime]::Today.AddDays(-90)
# 调整Filter逻辑,确保括号优先级,合并公共条件
$targetUsers = Get-ADUser -Filter {
    (Enabled -eq $true) -and 
    (PasswordNeverExpires -eq $false) -and 
    (WhenCreated -le $main_date) -and 
    (LastLogonDate -ne $null) -and 
    (LastLogonDate -ne [DateTime]::FromFileTime(0)) -and 
    ((PasswordLastSet -lt $main_date) -or (LastLogonTimestamp -lt $main_date))
} -Properties PasswordLastSet, LastLogonTimestamp, LastLogonDate, WhenCreated

# 输出需要的用户信息
$targetUsers | Select-Object SamAccountName, Name, @{
    Name = "LastLogonDate"
    Expression = {
        if ($_.LastLogonDate -eq [DateTime]::FromFileTime(0)) {
            'NeverLoggedIn'
        }
        else {
            $_.LastLogonDate.ToString("MM/dd/yyyy")
        }
    }
}

# 循环禁用账号
foreach ($user in $targetUsers) {
    Disable-ADAccount -Identity $user
}

方案2:使用筛选后的属性传递标识

如果需要保留Select-Object后的结果,循环时通过SamAccountName传递标识:

$main_date = [DateTime]::Today.AddDays(-90)
$DisabledUsers = Get-ADUser -Filter {
    (Enabled -eq $true) -and 
    (PasswordNeverExpires -eq $false) -and 
    (WhenCreated -le $main_date) -and 
    (LastLogonDate -ne $null) -and 
    (LastLogonDate -ne [DateTime]::FromFileTime(0)) -and 
    ((PasswordLastSet -lt $main_date) -or (LastLogonTimestamp -lt $main_date))
} -Properties PasswordLastSet, LastLogonTimestamp, LastLogonDate, WhenCreated |
Select-Object SamAccountName, Name, @{
    Name = "LastLogonDate"
    Expression = {
        if ($_.LastLogonDate -eq [DateTime]::FromFileTime(0)) {
            'NeverLoggedIn'
        }
        else {
            $_.LastLogonDate.ToString("MM/dd/yyyy")
        }
    }
}

echo $DisabledUsers

foreach ($user in $DisabledUsers) {
    Disable-ADAccount -Identity $user.SamAccountName
}

关键修正点

  1. Filter逻辑优化:将公共条件(启用状态、密码不永不过期等)提取到最外层,避免重复;用括号明确or的范围,防止逻辑歧义。
  2. 处理LastLogonDate的1601/1/1值:用[DateTime]::FromFileTime(0)直接判断,比字符串匹配更可靠。
  3. 传递正确的标识:方案1直接使用ADUser对象,方案2通过SamAccountName属性传递,确保Disable-ADAccount能识别。

内容的提问来源于stack exchange,提问作者Link

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 16:50:27