You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell导出单用户AD组到CSV时Get-ADPrincipalGroupMembership报未指定错误

错误原因
  • 标点符号问题:你代码里的引号用了中文全角格式的“/”,PowerShell无法正确识别字符串赋值,导致传入Get-ADPrincipalGroupMembership的用户名参数无效。
  • Get-ADPrincipalGroupMembership命令本身存在已知稳定性问题:当查询的用户所属组包含跨域组、残留无效SID、或当前执行脚本的账号没有该AD用户的属性读取权限时,就会抛出未指定的AD异常。
  • 潜在路径问题:如果导出路径C:\Input\EricsStuff\不存在,也会触发导出环节的错误(你当前报错出在Get命令阶段,该问题属于后续潜在风险)。
解决办法
  1. 先替换代码里所有中文全角引号为英文半角引号"。
  2. 更换更稳定的查询方式,用Get-ADUser读取用户的memberOf属性来获取所属组,避免触发Get-ADPrincipalGroupMembership的bug,修正后的代码如下:
Import-Module ActiveDirectory

$UserName = "pball"
$ReportPath = "C:\Input\EricsStuff\userADgroups.csv"

# 先判断目标路径是否存在,不存在则创建
$exportDir = Split-Path $ReportPath -Parent
if (-not (Test-Path $exportDir)) {
    New-Item -ItemType Directory -Path $exportDir | Out-Null
}

# 用Get-ADUser方式查询所属组,兼容异常场景
Get-ADUser -Identity $UserName -Properties memberOf | Select-Object -ExpandProperty memberOf | ForEach-Object {
    Get-ADGroup -Identity $_ -Properties name, groupcategory, groupscope
} | Select-Object name, groupcategory, groupscope | Export-Csv -Path $ReportPath -NoTypeInformation -Encoding UTF8
  1. 执行脚本时请用具备AD用户属性读取权限的账号运行,建议右键PowerShell选择「以管理员身份运行」后再执行脚本。

内容的提问来源于stack exchange,提问作者eric webster

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.25 05:54:02