PowerShell禁用90天未活动AD用户脚本报错求助
解决禁用90天未活动AD用户的PowerShell脚本错误
问题描述
编写了用于禁用90天以上未活动AD用户的PowerShell脚本,但执行时出现以下错误:
Disable-ADAccount : Cannot bind parameter 'Identity'. Cannot create object of type "Microsoft.ActiveDirectory.Management.ADAccount". The adapter cannot set the value of property "Name".
虽然echo $DisabledUsers能正确显示用户信息,但Disable-ADAccount无法识别筛选出的对象。
需要满足的检查条件:
核心条件
- PasswordLastSet属性早于90天
- LastLogonTimestamp属性早于90天
额外条件
- 账号处于启用状态
- 未设置密码永不过期属性
- LastLogonDate属性不为空
- LastLogonDate属性未设为1/1/1601
- 账号创建时间不早于90天
错误原因
脚本中使用Select-Object仅提取了部分属性,返回的是自定义PSObject对象,而非Microsoft.ActiveDirectory.Management.ADUser对象。Disable-ADAccount需要接收ADUser对象或可直接识别的标识(如SamAccountName),因此无法绑定参数。
修正后的脚本
方案1:保留原始ADUser对象(推荐)
先筛选出符合条件的ADUser对象,再输出需要的信息,最后循环禁用:
$main_date = [DateTime]::Today.AddDays(-90) # 调整Filter逻辑,确保括号优先级,合并公共条件 $targetUsers = Get-ADUser -Filter { (Enabled -eq $true) -and (PasswordNeverExpires -eq $false) -and (WhenCreated -le $main_date) -and (LastLogonDate -ne $null) -and (LastLogonDate -ne [DateTime]::FromFileTime(0)) -and ((PasswordLastSet -lt $main_date) -or (LastLogonTimestamp -lt $main_date)) } -Properties PasswordLastSet, LastLogonTimestamp, LastLogonDate, WhenCreated # 输出需要的用户信息 $targetUsers | Select-Object SamAccountName, Name, @{ Name = "LastLogonDate" Expression = { if ($_.LastLogonDate -eq [DateTime]::FromFileTime(0)) { 'NeverLoggedIn' } else { $_.LastLogonDate.ToString("MM/dd/yyyy") } } } # 循环禁用账号 foreach ($user in $targetUsers) { Disable-ADAccount -Identity $user }
方案2:使用筛选后的属性传递标识
如果需要保留Select-Object后的结果,循环时通过SamAccountName传递标识:
$main_date = [DateTime]::Today.AddDays(-90) $DisabledUsers = Get-ADUser -Filter { (Enabled -eq $true) -and (PasswordNeverExpires -eq $false) -and (WhenCreated -le $main_date) -and (LastLogonDate -ne $null) -and (LastLogonDate -ne [DateTime]::FromFileTime(0)) -and ((PasswordLastSet -lt $main_date) -or (LastLogonTimestamp -lt $main_date)) } -Properties PasswordLastSet, LastLogonTimestamp, LastLogonDate, WhenCreated | Select-Object SamAccountName, Name, @{ Name = "LastLogonDate" Expression = { if ($_.LastLogonDate -eq [DateTime]::FromFileTime(0)) { 'NeverLoggedIn' } else { $_.LastLogonDate.ToString("MM/dd/yyyy") } } } echo $DisabledUsers foreach ($user in $DisabledUsers) { Disable-ADAccount -Identity $user.SamAccountName }
关键修正点
- Filter逻辑优化:将公共条件(启用状态、密码不永不过期等)提取到最外层,避免重复;用括号明确
or的范围,防止逻辑歧义。 - 处理LastLogonDate的1601/1/1值:用
[DateTime]::FromFileTime(0)直接判断,比字符串匹配更可靠。 - 传递正确的标识:方案1直接使用ADUser对象,方案2通过
SamAccountName属性传递,确保Disable-ADAccount能识别。
内容的提问来源于stack exchange,提问作者Link
相关产品推荐
相关产品推荐

