You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Windows内置命令(无需PowerShell)获取Active Directory信息

无需额外组件的AD信息查询方案

实现前提

依赖Windows系统自带的.NET System.DirectoryServices 相关类,所有默认PowerShell环境(无需安装AD模块、第三方工具)均可直接使用,无需额外配置。

常用查询代码

查询当前登录用户的邮箱地址

# 加载账户管理程序集
Add-Type -AssemblyName System.DirectoryServices.AccountManagement
# 获取当前用户的AD主体对象
$currentUser = [System.DirectoryServices.AccountManagement.UserPrincipal]::Current
# 输出邮箱地址
$currentUser.EmailAddress

按指定LDAP路径查询任意属性

适合你已经通过AD Explorer拿到目标对象完整LDAP路径的场景:

# 替换为你实际获取到的完整LDAP路径
$targetLdapPath = "ldap://CN=TestUser,OU=IT,DC=corp,DC=com"
# 替换为要查询的属性名,邮箱对应属性通常为mail
$attrName = "mail"

# 绑定目标AD对象
$adObject = New-Object System.DirectoryServices.DirectoryEntry($targetLdapPath)
# 读取对应属性的值
$attrValue = $adObject.Properties[$attrName].Value
# 输出查询结果
$attrValue

补充说明

  • 若需要查询目标对象的所有可用属性,直接输出$adObject.Properties即可查看完整属性列表和对应值
  • 若遇到权限报错,使用有对应AD对象访问权限的域用户运行PowerShell即可解决
  • 该方法兼容所有加入域的Windows设备,支持PowerShell 2.0及以上所有版本,无额外依赖

内容的提问来源于stack exchange,提问作者Max

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.23 23:24:03