PowerShell本地管理员密码修改脚本及日志功能开发求助
Solution Script
Here's a revised script that fixes the logging issues and properly handles password updates for both accounts:
$NewPassword = ConvertTo-SecureString "*****" -AsPlainText -Force $hostname = [System.Net.Dns]::GetHostEntry($env:COMPUTERNAME).HostName $networkLogPath = "\\ctdc01\install\pwupdate.txt" function Log-Message { param( [Parameter(Mandatory=$true)] [string]$Message, [string]$LogPath = $networkLogPath ) $timestamp = Get-Date -Format "yyyy-MM-dd HH:mm:ss" $logEntry = "[$timestamp] $Message" try { # Write to network share first Add-Content -Path $LogPath -Value $logEntry -ErrorAction Stop } catch { # Fallback to local temp log if network access fails $localLogPath = Join-Path -Path $env:TEMP -ChildPath "pwupdate_fallback.log" $fallbackMessage = "[$timestamp] NETWORK LOG FAILURE: $_ | Original Message: $Message" Add-Content -Path $localLogPath -Value $fallbackMessage -ErrorAction SilentlyContinue } } Log-Message "Initiating password update process on $hostname" # Update Usertech account password try { Set-LocalUser -Name "Usertech" -Password $NewPassword -ErrorAction Stop Log-Message "Successfully updated password for 'Usertech' on $hostname" } catch { Log-Message "Failed to update password for 'Usertech' on $hostname : $_" } # Update support account password try { Set-LocalUser -Name "support" -Password $NewPassword -ErrorAction Stop Log-Message "Successfully updated password for 'support' on $hostname" } catch { Log-Message "Failed to update password for 'support' on $hostname : $_" } Log-Message "Completed password update process on $hostname"
Key Fixes & Improvements
- Network Log Target: Changed log path to your required network share
\\ctdc01\install\pwupdate.txt - Error Handling: Added
try/catchblocks for both password changes and log writes to capture failures - Fallback Logging: If the network share is unavailable, logs save to a local temp file as a backup
- Hostname Inclusion: Uses the full machine hostname (including domain) in all log entries
- Account Coverage: Processes both
Usertechandsupportaccounts as specified - Timestamped Entries: Adds timestamps to log entries for better auditability
Troubleshooting Tips
- Share Permissions: Ensure the RMM agent's execution context (usually local system account) has write permissions to
\\ctdc01\install. Grant access to the machine account (DOMAIN\MACHINENAME$) if the agent runs as local system. - Account Existence: Verify
Usertechandsupportlocal accounts exist on target machines—missing accounts will trigger a logged failure. - Network Access: Confirm target machines can resolve
ctdc01via DNS and reach the share (no firewall rules blocking SMB traffic). - Password Complexity: Ensure the new password meets local machine password complexity requirements (if enabled).
内容的提问来源于stack exchange,提问作者Justin Harris
相关产品推荐
相关产品推荐

