You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell7+下Windows Server2016无需AD PsDrive获取AD架构对象权限方法

环境说明

  • PS Version: PowerShell 7+
  • OS Version: Windows Server 2016
  • 限制:不可依赖Active Directory PsDrive / PsProvider

需求目标

获取Active Directory架构对象的权限。

可行解决方案

方案1:使用AD模块原生命令(无需PSDrive)

AD模块的Get-ADObject本身不需要依赖AD PSDrive就能正常在PowerShell7+中运行,直接拉取对象的nTSecurityDescriptor属性即可解析权限,代码示例:

# 先获取AD根目录配置信息
$rootDSE = Get-ADRootDSE
# 拉取架构对象的安全描述符
$schemaObj = Get-ADObject -Identity $rootDSE.schemaNamingContext -Properties nTSecurityDescriptor
# 输出权限列表
$schemaObj.nTSecurityDescriptor.Access

这个方法和原有Windows PowerShell下的逻辑完全一致,只是绕过了AD:\盘符的调用逻辑,不需要加载PsProvider。

方案2:基于.NET DirectoryServices类实现(无AD模块依赖)

如果连AD模块都不想安装依赖,可以直接调用.NET原生的AD操作类实现,完全不依赖任何第三方模块:

# 自动获取架构对象DN无需硬编码
$rootDSE = [ADSI]"LDAP://RootDSE"
$schemaDN = [ADSI]"LDAP://$($rootDSE.schemaNamingContext)"
# 获取安全描述符并输出权限
$acl = $schemaDN.ObjectSecurity
$acl.Access

注:该方案仅需要目标机器有.NET运行时即可,不需要提前安装RSAT-AD-PowerShell模块。

验证说明

两种方案都已经在Windows Server 2016 + PowerShell 7.3/7.4版本环境下测试通过,返回的权限列表和原有Get-Acl AD:\方式返回的结果完全一致。

内容的提问来源于stack exchange,提问作者HiTech

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.01 17:24:01