You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何利用ConvertTo-SecureString生成的加密凭据加入域?

Join Domain Using Stored Encrypted Credentials

Got it, let's walk through how to use your existing $MyCredential variable to join a domain without admin intervention. Here's what you need to do:

Step 1: Verify Your Credential Object First

First, confirm your $MyCredential is properly built from the encrypted password file. Your current script works for same-machine, same-user scenarios, but keep this critical note in mind:

By default, ConvertTo-SecureString uses the current user's context and local machine encryption key to decrypt the stored string. If you generated the encrypted password file on a different machine or with another user, decryption will fail. I'll cover a cross-machine fix later.

Step 2: Use Add-Computer to Join the Domain

Once your $MyCredential is ready, use the Add-Computer cmdlet to complete the domain join. This is the core command you need:

# Replace "YourDomainName.com" with your actual domain
Add-Computer -DomainName "YourDomainName.com" -Credential $MyCredential -Restart -Force

Parameter Breakdown:

  • -DomainName: The fully qualified name of your Active Directory domain (e.g., corp.example.com).
  • -Credential: Passes your pre-built $MyCredential object to authenticate against the domain.
  • -Restart: Automatically restarts the machine after joining (required for the domain join to take effect).
  • -Force: Skips interactive confirmation prompts, ideal for unattended deployments.

Fix for Cross-Machine/Non-User-Specific Encryption

If you're deploying the encrypted password file to a different machine or need it to work across users, the default encryption won't suffice. Instead, use an AES key for consistent encryption/decryption:

On the machine generating the encrypted password:

# Create a 32-byte AES key (save this securely and deploy it to the target machine)
$aesKey = New-Object Byte[] 32
[System.Security.Cryptography.RNGCryptoServiceProvider]::Create().GetBytes($aesKey)
$aesKey | Out-File "C:\Temp\AESKey.txt"

# Encrypt the password with the AES key and save it
$plainPassword = 'P@ssw0rd'
$securePassword = ConvertTo-SecureString $plainPassword -AsPlainText -Force
$securePassword | ConvertFrom-SecureString -Key $aesKey | Out-File "C:\Temp\Password.txt"

On the target machine to reconstruct the credential:

# Load the AES key and encrypted password
$aesKey = Get-Content "C:\Temp\AESKey.txt"
$encryptedPassword = Get-Content "C:\Temp\Password.txt"

# Convert back to a SecureString and create the credential
$securePassword = ConvertTo-SecureString $encryptedPassword -Key $aesKey
$MyCredential = New-Object System.Management.Automation.PSCredential("MyUserName", $securePassword)

# Join the domain using the credential
Add-Computer -DomainName "YourDomainName.com" -Credential $MyCredential -Restart -Force

Key Notes

  • The script must run with local administrator privileges on the target machine (required to modify machine settings for domain join).
  • Ensure the target machine has network connectivity to your domain controllers.
  • Store the AES key securely (e.g., in a secure vault) — anyone with access to it can decrypt the password.

内容的提问来源于stack exchange,提问作者Wiktor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:59:27