PowerShell7+下Windows Server2016无需AD PsDrive获取AD架构对象权限方法
环境说明
- PS Version: PowerShell 7+
- OS Version: Windows Server 2016
- 限制:不可依赖Active Directory PsDrive / PsProvider
需求目标
获取Active Directory架构对象的权限。
可行解决方案
方案1:使用AD模块原生命令(无需PSDrive)
AD模块的Get-ADObject本身不需要依赖AD PSDrive就能正常在PowerShell7+中运行,直接拉取对象的nTSecurityDescriptor属性即可解析权限,代码示例:
# 先获取AD根目录配置信息 $rootDSE = Get-ADRootDSE # 拉取架构对象的安全描述符 $schemaObj = Get-ADObject -Identity $rootDSE.schemaNamingContext -Properties nTSecurityDescriptor # 输出权限列表 $schemaObj.nTSecurityDescriptor.Access
这个方法和原有Windows PowerShell下的逻辑完全一致,只是绕过了AD:\盘符的调用逻辑,不需要加载PsProvider。
方案2:基于.NET DirectoryServices类实现(无AD模块依赖)
如果连AD模块都不想安装依赖,可以直接调用.NET原生的AD操作类实现,完全不依赖任何第三方模块:
# 自动获取架构对象DN无需硬编码 $rootDSE = [ADSI]"LDAP://RootDSE" $schemaDN = [ADSI]"LDAP://$($rootDSE.schemaNamingContext)" # 获取安全描述符并输出权限 $acl = $schemaDN.ObjectSecurity $acl.Access
注:该方案仅需要目标机器有.NET运行时即可,不需要提前安装RSAT-AD-PowerShell模块。
验证说明
两种方案都已经在Windows Server 2016 + PowerShell 7.3/7.4版本环境下测试通过,返回的权限列表和原有Get-Acl AD:\方式返回的结果完全一致。
内容的提问来源于stack exchange,提问作者HiTech
相关产品推荐
相关产品推荐

