如何为新建用户分配管理员权限并设置PasswordNeverExpires为true
解决方案
方法一:结合UserPrincipal与DirectoryEntry实现需求
先用UserPrincipal完成用户创建、密码设置及PasswordNeverExpires配置,再通过DirectoryEntry将用户加入本地管理员组:
class Program { public static string Name; public static string Pass; static void Main(string[] args) { Name = "Test1"; Pass = "Test2"; CreateUser(Name, Pass); } public static void CreateUser(string userName, string password) { try { using (PrincipalContext ctx = new PrincipalContext(ContextType.Machine)) { // 创建用户并设置基础属性 UserPrincipal newUser = new UserPrincipal(ctx); newUser.SamAccountName = userName; newUser.SetPassword(password); newUser.Enabled = true; newUser.PasswordNeverExpires = true; newUser.Save(); // 获取用户对应的DirectoryEntry对象 DirectoryEntry userEntry = newUser.GetUnderlyingObject() as DirectoryEntry; // 获取本地管理员组 GroupPrincipal adminGroup = GroupPrincipal.FindByIdentity(ctx, "Administrators"); if (adminGroup != null) { // 将用户添加到管理员组 adminGroup.Members.Add(newUser); adminGroup.Save(); } Console.WriteLine("用户创建完成并已添加至管理员组"); } } catch (Exception ex) { Console.WriteLine(ex.Message); Console.ReadLine(); } } }
方法二:纯DirectoryEntry实现所有需求
直接使用DirectoryEntry操作AD对象,通过设置userAccountControl属性实现密码永不过期,同时将用户加入管理员组:
class Program { public static string Name; public static string Pass; static void Main(string[] args) { Name = "Test1"; Pass = "Test2"; CreateUser(Name, Pass); } public static void CreateUser(string userName, string password) { try { // 连接到本地机器的用户容器 using (DirectoryEntry machineEntry = new DirectoryEntry("WinNT://./computer,computer")) { // 创建新用户 DirectoryEntry newUser = machineEntry.Children.Add(userName, "user"); newUser.Invoke("SetPassword", new object[] { password }); newUser.Properties["Enabled"].Value = true; // 设置密码永不过期:修改userAccountControl属性,添加ADS_UF_DONT_EXPIRE_PASSWD(0x10000)标识 int userAccountControl = (int)newUser.Properties["userAccountControl"].Value; newUser.Properties["userAccountControl"].Value = userAccountControl | 0x10000; newUser.CommitChanges(); // 获取管理员组并添加用户 DirectoryEntry adminGroup = machineEntry.Children.Find("Administrators", "group"); adminGroup.Invoke("Add", new object[] { newUser.Path }); adminGroup.CommitChanges(); Console.WriteLine("用户创建完成并已添加至管理员组"); } } catch (Exception ex) { Console.WriteLine(ex.Message); Console.ReadLine(); } } }
关键说明
userAccountControl属性是AD用户的控制位集合,0x10000对应密码永不过期的标识,通过按位或操作添加该标识即可实现需求。- 添加管理员组时,两种方法都是找到管理员组对象后,将用户加入成员列表并保存变更。
内容的提问来源于stack exchange,提问作者AliExpresz
相关产品推荐
相关产品推荐

