如何通过PowerShell将用户添加至管理员组及解决相关报错
Hey there! Let's break down how to add users to the local Administrators group with PowerShell, plus fix that frustrating error you're encountering.
First: Fixing Your Error
The 无法找到组名 error you're seeing almost certainly stems from an incorrect user path in your code. When you hardcode $DomainName = "xxxx", if that doesn't match the actual domain (or local machine name, for local users), PowerShell can't locate the user object $InUser—so calling $AdminGroup.Add() fails. We'll fix this in the solutions below.
1. Add a Specific User to the Local Administrators Group
We'll cover two common scenarios: local users and domain users.
Scenario 1: Add a Local User
For users that exist directly on the local machine, use . to represent the local system, or the machine's name:
# Replace with your target local username $targetUser = "LocalUserName" $computerName = $env:COMPUTERNAME # Get the local Administrators group object $adminGroup = [ADSI]"WinNT://$computerName/Administrators,group" # Get the target local user object $user = [ADSI]"WinNT://./$targetUser,user" # Execute the addition try { $adminGroup.Add($user.Path) Write-Host "Successfully added user $targetUser to Administrators group" } catch { Write-Host "Failed to add user: $_" }
Scenario 2: Add a Domain User
For users from an Active Directory domain, make sure to use the correct domain name:
# Replace with your domain username and actual domain name $targetUser = "DomainUserName" $domainName = "YourDomainName" $computerName = $env:COMPUTERNAME $adminGroup = [ADSI]"WinNT://$computerName/Administrators,group" # Format for domain users: WinNT://DomainName/UserName $user = [ADSI]"WinNT://$domainName/$targetUser,user" try { $adminGroup.Add($user.Path) Write-Host "Successfully added domain user $domainName\$targetUser to local Administrators group" } catch { Write-Host "Failed to add user: $_" }
2. Add Your Current Logged-In User to Administrators
If you want to grant admin rights to yourself (the currently logged-in user), we can auto-detect whether you're a local or domain user:
$currentUser = $env:USERNAME $computerName = $env:COMPUTERNAME $userDomain = $env:USERDOMAIN $adminGroup = [ADSI]"WinNT://$computerName/Administrators,group" # Check if we're dealing with a local or domain user if ($userDomain -eq $computerName) { # Local user: use "." for the local machine $user = [ADSI]"WinNT://./$currentUser,user" } else { # Domain user: use the detected domain name $user = [ADSI]"WinNT://$userDomain/$currentUser,user" } try { $adminGroup.Add($user.Path) Write-Host "Successfully added current user $userDomain\$currentUser to Administrators group" } catch { # Handle the case where the user is already in the group if ($_.Exception.Message -match "already a member") { Write-Host "Current user is already an Administrator" } else { Write-Host "Failed to add user: $_" } }
Why Your Original Code Failed
Your hardcoded $DomainName = "xxxx" was the issue. If you're a local user, this value didn't match your machine's name; if you're a domain user, it wasn't your actual domain name. Using $env:USERDOMAIN automatically pulls the correct domain/machine name for your current user, eliminating this mismatch.
内容的提问来源于stack exchange,提问作者TropicalViking

