如何用VBScript获取AD中各用户经理的sAMAccountName而非DN
Got it, let's sort this out for you! Right now, grabbing the manager field gives you the full distinguished name (DN) of the manager, which isn't what you need. There are two solid ways to get their sAMAccountName instead—one that's rock-solid reliable, and another quick-and-dirty option (with caveats).
Method 1: Direct AD Query (Recommended)
This is the best approach because it directly fetches the sAMAccountName attribute from the manager's AD record, avoiding any parsing issues. Here's how to implement it:
' Assuming you already have your main user recordset open from your initial AD query Dim strManagerDN, objManagerConn, objManagerRS, strManagerSamAccountName strManagerDN = objRecordSet.Fields("manager").Value ' Only proceed if the user actually has a manager assigned If Not IsNull(strManagerDN) Then ' Set up a new AD connection for the manager lookup Set objManagerConn = CreateObject("ADODB.Connection") objManagerConn.Open "Provider=ADsDSOObject;" ' Build a query targeting the manager's DN to get their sAMAccountName strManagerQuery = "<LDAP://" & strManagerDN & ">;sAMAccountName;subtree" Set objManagerRS = CreateObject("ADODB.Recordset") objManagerRS.Open strManagerQuery, objManagerConn ' Grab the value if the recordset isn't empty If Not objManagerRS.EOF Then strManagerSamAccountName = objManagerRS.Fields("sAMAccountName").Value ' Use the value however you need—example below WScript.Echo "User's Manager (sAMAccountName): " & strManagerSamAccountName End If ' Clean up objects to avoid memory leaks objManagerRS.Close Set objManagerRS = Nothing objManagerConn.Close Set objManagerConn = Nothing End If
Why this works: It targets the exact manager object via their DN and only pulls the sAMAccountName attribute, so you don't have to worry about mismatches between the manager's CN (common name) and their logon name.
Method 2: Parse the Distinguished Name (Quick but Risky)
If you're in a pinch and know for sure that your AD uses the same value for CN and sAMAccountName, you can parse the DN directly. Warning: This will fail if the manager's CN doesn't match their sAMAccountName, or if their DN contains escaped characters (like a comma written as \,).
strManagerDN = objRecordSet.Fields("manager").Value If Not IsNull(strManagerDN) Then ' Split the DN into components using commas as separators arrDNComponents = Split(strManagerDN, ",") ' The first component is usually CN=Username strCNComponent = arrDNComponents(0) ' Split the CN component to extract the username arrCNParts = Split(strCNComponent, "=") strManagerSamAccountName = arrCNParts(1) ' Example usage WScript.Echo "Parsed Manager sAMAccountName: " & strManagerSamAccountName End If
Stick with Method 1 for production code—it's far more robust.
内容的提问来源于stack exchange,提问作者ITMAn

