请求为现有可用PowerShell脚本添加pwdlastset输出字段
给AD用户脚本添加pwdlastset字段的修改方案
要在现有脚本的输出结果里添加pwdlastset(最后修改密码时间)字段,只需在用户属性选择的环节新增一个对应的计算属性即可。修改后的完整脚本如下:
$NumDays = 90 $LogDir = ".\HaveNotLoggedInFor90Days.csv" $currentDate = [System.DateTime]::Now $currentDateUtc = $currentDate.ToUniversalTime() $lltstamplimit = $currentDateUtc.AddDays(- $NumDays) $lltIntLimit = $lltstampLimit.ToFileTime() $adobjroot = [adsi]'' $objstalesearcher = New-Object System.DirectoryServices.DirectorySearcher($adobjroot) $objstalesearcher.filter = "(&(objectCategory=person)(objectClass=user)(lastLogonTimeStamp<=" + $lltIntLimit + "))" $users = $objstalesearcher.findall() | select ` @{e={$_.properties.cn};n='Display Name'},` @{e={$_.properties.samaccountname};n='Username'},` @{e={[datetime]::FromFileTimeUtc([int64]$_.properties.lastlogontimestamp[0])};n='Last Logon'},` @{e={[string]$adspath=$_.properties.adspath;$account=[ADSI]$adspath;$account.psbase.invokeget('AccountDisabled')};n='Account Is Disabled'},` @{e={if($_.properties.pwdlastset){[datetime]::FromFileTimeUtc([int64]$_.properties.pwdlastset[0])} else {$null}};n='Last Password Set'} $users | Export-CSV -NoType $LogDir
修改说明
新增的代码行做了这些事:
- 读取AD用户对象的
pwdlastset属性 - 把AD存储的文件时间格式转换成可读的UTC日期时间(和
Last Logon字段的处理逻辑一致) - 增加空值判断:如果用户没有
pwdlastset属性(比如部分系统账户),就返回空值,避免脚本运行报错
内容的提问来源于stack exchange,提问作者Sean
相关产品推荐
相关产品推荐

