查询Active Directory用户时AccountExpires属性为空,是否为正确取值属性?
解答
核心问题答复
AccountExpires是Active Directory中存储用户账户到期时间的正确原生属性,查询返回空值是该属性的存储特性和默认值规则导致的:
- 该属性存储的是100纳秒精度的FILETIME整数时间戳,并非直接可读的日期格式
- 若用户账户未设置到期时间,AccountExpires的默认值为
0或9223372036854775807,这两个特殊值会被识别为无效日期,导出CSV时就会显示为空,对应账户「永不过期」的状态
修正后的查询脚本
可以通过计算属性将FILETIME转换为可读日期,同时区分永不过期的状态:
Get-ADUser -Filter '*' -Properties DisplayName, title, Department, Office, OfficePhone, EmailAddress, wWWHomePage, AccountExpires -SearchBase '****' | Sort-Object -Property DisplayName | Select-Object -Property DisplayName, Title, Department, Office, OfficePhone, EmailAddress, wWWHomePage, @{ Name = '账户到期时间' Expression = { if ($_.AccountExpires -eq 0 -or $_.AccountExpires -eq 9223372036854775807) { return "永不过期" } return [DateTime]::FromFileTime($_.AccountExpires) } } | Export-Csv -LiteralPath C:\PowerShell\temp1.csv -NoTypeInformation -Encoding UTF8
简化方案
AD PowerShell模块已经内置了转换好的可读日期属性AccountExpirationDate,你可以直接替换查询的属性,无需手动处理FILETIME格式:
# 仅需将查询属性替换为AccountExpirationDate即可 Get-ADUser -Filter '*' -Properties DisplayName, title, Department, Office, OfficePhone, EmailAddress, wWWHomePage, AccountExpirationDate -SearchBase '****' | Sort-Object -Property DisplayName | Select-Object DisplayName, Title, Department, Office, OfficePhone, EmailAddress, wWWHomePage, AccountExpirationDate | Export-Csv -LiteralPath C:\PowerShell\temp1.csv -NoTypeInformation -Encoding UTF8
内容的提问来源于stack exchange,提问作者MoellerB
相关产品推荐
相关产品推荐

