You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为新建用户分配管理员权限并设置PasswordNeverExpires为true

解决方案

方法一:结合UserPrincipal与DirectoryEntry实现需求

先用UserPrincipal完成用户创建、密码设置及PasswordNeverExpires配置,再通过DirectoryEntry将用户加入本地管理员组:

class Program
{
    public static string Name;
    public static string Pass;

    static void Main(string[] args)
    {
        Name = "Test1";
        Pass = "Test2";
        CreateUser(Name, Pass);
    }

    public static void CreateUser(string userName, string password)
    {
        try
        {
            using (PrincipalContext ctx = new PrincipalContext(ContextType.Machine))
            {
                // 创建用户并设置基础属性
                UserPrincipal newUser = new UserPrincipal(ctx);
                newUser.SamAccountName = userName;
                newUser.SetPassword(password);
                newUser.Enabled = true;
                newUser.PasswordNeverExpires = true;
                newUser.Save();

                // 获取用户对应的DirectoryEntry对象
                DirectoryEntry userEntry = newUser.GetUnderlyingObject() as DirectoryEntry;

                // 获取本地管理员组
                GroupPrincipal adminGroup = GroupPrincipal.FindByIdentity(ctx, "Administrators");
                if (adminGroup != null)
                {
                    // 将用户添加到管理员组
                    adminGroup.Members.Add(newUser);
                    adminGroup.Save();
                }

                Console.WriteLine("用户创建完成并已添加至管理员组");
            }
        }
        catch (Exception ex)
        {
            Console.WriteLine(ex.Message);
            Console.ReadLine();
        }
    }
}

方法二:纯DirectoryEntry实现所有需求

直接使用DirectoryEntry操作AD对象,通过设置userAccountControl属性实现密码永不过期,同时将用户加入管理员组:

class Program
{
    public static string Name;
    public static string Pass;

    static void Main(string[] args)
    {
        Name = "Test1";
        Pass = "Test2";
        CreateUser(Name, Pass);
    }

    public static void CreateUser(string userName, string password)
    {
        try
        {
            // 连接到本地机器的用户容器
            using (DirectoryEntry machineEntry = new DirectoryEntry("WinNT://./computer,computer"))
            {
                // 创建新用户
                DirectoryEntry newUser = machineEntry.Children.Add(userName, "user");
                newUser.Invoke("SetPassword", new object[] { password });
                newUser.Properties["Enabled"].Value = true;

                // 设置密码永不过期:修改userAccountControl属性,添加ADS_UF_DONT_EXPIRE_PASSWD(0x10000)标识
                int userAccountControl = (int)newUser.Properties["userAccountControl"].Value;
                newUser.Properties["userAccountControl"].Value = userAccountControl | 0x10000;

                newUser.CommitChanges();

                // 获取管理员组并添加用户
                DirectoryEntry adminGroup = machineEntry.Children.Find("Administrators", "group");
                adminGroup.Invoke("Add", new object[] { newUser.Path });
                adminGroup.CommitChanges();

                Console.WriteLine("用户创建完成并已添加至管理员组");
            }
        }
        catch (Exception ex)
        {
            Console.WriteLine(ex.Message);
            Console.ReadLine();
        }
    }
}

关键说明

  • userAccountControl属性是AD用户的控制位集合,0x10000对应密码永不过期的标识,通过按位或操作添加该标识即可实现需求。
  • 添加管理员组时,两种方法都是找到管理员组对象后,将用户加入成员列表并保存变更。

内容的提问来源于stack exchange,提问作者AliExpresz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 13:31:08