You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用PowerShell获取远程服务器本地用户及所属组成员身份

兼容旧版PowerShell的高速查询方案

用WinNT ADSI接口实现即可满足需求,兼容PowerShell 2.0及以上所有版本,不需要依赖新版自带的Microsoft.PowerShell.LocalAccounts模块,查询速度远快于WMI查询方式:gwmi Win32_UserAccount默认会遍历当前域及信任域下的所有账号数据,拉取大量无关内容,ADSI方式直连目标主机的本地SAM安全库,仅读取目标主机本地的用户、组关联数据,无冗余查询。

完整脚本

param(
    [Parameter(Mandatory=$true)]
    [string]$ComputerName
)

# 连接目标计算机本地安全存储
$adsiPath = "WinNT://$ComputerName,computer"
$machine = [ADSI]$adsiPath

# 枚举所有本地用户及所属组
$localUsers = $machine.Children | Where-Object { $_.SchemaClassName -eq 'User' } | ForEach-Object {
    $groupList = @()
    # 遍历当前用户关联的所有用户组
    $_.Groups() | ForEach-Object {
        $groupPath = $_.GetType().InvokeMember('Adspath', 'GetProperty', $null, $_, $null)
        $group = [ADSI]$groupPath
        $groupList += $group.Name.Value
    }
    # 构造固定格式输出对象
    New-Object PSObject -Property @{
        User     = $_.Name.Value
        Memberof = $groupList -join ','
    } | Select-Object User,Memberof
}

# 按表格格式输出结果
$localUsers | Format-Table -AutoSize

使用方式

  • 查询本机:传入.或者本机计算机名作为参数,执行.\Get-LocalUserInfo.ps1 -ComputerName .
  • 查询远程主机:传入目标主机的IP或计算机名即可,执行.\Get-LocalUserInfo.ps1 -ComputerName 目标主机名或IP
  • 批量查询:在外层套服务器列表循环即可,单台主机查询耗时通常在1秒以内。

输出效果

User Memberof                                   
---- --------                                   
a    Administrators                            
b    Remote Desktop Users                       
c    Administrators,Backup Operators,Users      
6    Remote Desktop Users,Backup Operators      

注意:执行脚本的账号需要拥有目标主机的本地管理员权限,远程查询需要目标主机开放RPC远程管理端口(默认135、445及动态RPC端口,和常规WMI远程管理的端口要求一致)。

内容的提问来源于stack exchange,提问作者Mohamed Faisal A

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.28 10:06:29