You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求协助编写PowerShell脚本导出特定组外的启用AD用户

Export Enabled AD Users Not in a Specific Group to CSV

Let's work through your AD export request step by step. PowerShell is the most reliable tool for this kind of AD query, so I'll share two practical methods—one simple for small-to-medium environments, and a faster bulk approach for large directories.

Prerequisites

First, make sure you have the Active Directory PowerShell module installed:

  • On a domain controller, it's usually pre-installed.
  • On Windows 10/11, add it via Settings > Apps > Optional features > Search for "RSAT: Active Directory Domain Services and Lightweight Directory Tools".
  • Or run this in an elevated PowerShell window:
    Install-WindowsFeature RSAT-AD-PowerShell
    

You'll also need to run PowerShell as a user with permissions to read AD user and group data.

Method 1: Direct Membership Check (Simple)

This script checks each enabled user's group membership individually—great for smaller AD environments where speed isn't a critical concern:

# Replace these with your group name and desired CSV output path
$excludedGroupName = "Your-Target-Group-Name"
$outputCsvPath = "C:\AD_Exports\Enabled_Users_Not_In_Group.csv"

# Get the group's distinguished name to avoid conflicts (e.g., duplicate group names in different OUs)
$excludedGroupDN = (Get-ADGroup -Filter "Name -eq '$excludedGroupName'").DistinguishedName

# Query enabled users, filter out those in the excluded group, export to CSV
Get-ADUser -Filter { Enabled -eq $true } -Properties EmailAddress |
    Where-Object {
        # Keep only users NOT in the excluded group
        -not (Get-ADPrincipalGroupMembership $_ | Where-Object { $_.DistinguishedName -eq $excludedGroupDN })
    } |
    Select-Object SamAccountName, EmailAddress |
    Export-Csv -Path $outputCsvPath -NoTypeInformation -Encoding UTF8

Key Details:

  • SamAccountName: This is the "账户名" field you requested (it's the standard AD logon name).
  • EmailAddress: Included by adding -Properties EmailAddress since it's not a default AD user property.
  • UTF8 Encoding: Ensures special characters in names/emails are preserved correctly in the CSV.

Method 2: Bulk Membership Check (Faster for Large AD)

If you have thousands of users, Method 1 can be slow. This approach first fetches all members of the excluded group, then compares against all enabled users—far more efficient:

$excludedGroupName = "Your-Target-Group-Name"
$outputCsvPath = "C:\AD_Exports\Enabled_Users_Not_In_Group.csv"

# Get all members of the excluded group (add -Recursive to include nested subgroups)
$excludedGroupMembers = Get-ADGroupMember -Identity $excludedGroupName -Recursive |
    Select-Object -ExpandProperty SamAccountName

# Fetch enabled users and exclude those in the group member list
Get-ADUser -Filter { Enabled -eq $true } -Properties EmailAddress |
    Where-Object { $excludedGroupMembers -notcontains $_.SamAccountName } |
    Select-Object SamAccountName, EmailAddress |
    Export-Csv -Path $outputCsvPath -NoTypeInformation -Encoding UTF8

Quick Note:

Remove the -Recursive flag from Get-ADGroupMember if you only want to exclude direct group members (not users in nested subgroups).

Troubleshooting Tips

  • Module not found error: Double-check that the Active Directory PowerShell module is installed (see prerequisites).
  • No results returned: Verify your group name is spelled correctly, and confirm there are enabled users not part of that group.
  • Empty email fields: This means the user's email address isn't populated in AD—this is expected behavior, not an error.

内容的提问来源于stack exchange,提问作者Marshall

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:23:49