You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求为现有可用PowerShell脚本添加pwdlastset输出字段

给AD用户脚本添加pwdlastset字段的修改方案

要在现有脚本的输出结果里添加pwdlastset(最后修改密码时间)字段,只需在用户属性选择的环节新增一个对应的计算属性即可。修改后的完整脚本如下:

$NumDays = 90
$LogDir = ".\HaveNotLoggedInFor90Days.csv"

$currentDate = [System.DateTime]::Now
$currentDateUtc = $currentDate.ToUniversalTime()
$lltstamplimit = $currentDateUtc.AddDays(- $NumDays)
$lltIntLimit = $lltstampLimit.ToFileTime()
$adobjroot = [adsi]''
$objstalesearcher = New-Object System.DirectoryServices.DirectorySearcher($adobjroot)
$objstalesearcher.filter = "(&(objectCategory=person)(objectClass=user)(lastLogonTimeStamp<=" + $lltIntLimit + "))"

$users = $objstalesearcher.findall() | select `
@{e={$_.properties.cn};n='Display Name'},`
@{e={$_.properties.samaccountname};n='Username'},`
@{e={[datetime]::FromFileTimeUtc([int64]$_.properties.lastlogontimestamp[0])};n='Last Logon'},`
@{e={[string]$adspath=$_.properties.adspath;$account=[ADSI]$adspath;$account.psbase.invokeget('AccountDisabled')};n='Account Is Disabled'},`
@{e={if($_.properties.pwdlastset){[datetime]::FromFileTimeUtc([int64]$_.properties.pwdlastset[0])} else {$null}};n='Last Password Set'}

$users | Export-CSV -NoType $LogDir

修改说明

新增的代码行做了这些事:

  • 读取AD用户对象的pwdlastset属性
  • 把AD存储的文件时间格式转换成可读的UTC日期时间(和Last Logon字段的处理逻辑一致)
  • 增加空值判断:如果用户没有pwdlastset属性(比如部分系统账户),就返回空值,避免脚本运行报错

内容的提问来源于stack exchange,提问作者Sean

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 20:54:14