使用PowerShell创建DomainLocal类型AD组失败求助
Troubleshooting & Fixing Your AD Group Creation Script
Let’s walk through why your DomainLocal AD group isn’t being created, even without error messages, and fix the issues step by step:
1. The Most Likely Culprit: A Hidden Space in Your Folder Path
Look closely at how you define $ProjectFolder:
$ProjectFolder = " $Folder\$($ProjectName)"
There’s an extra leading space before $Folder! This makes your path evaluate to something like " C:\FunctionOutputs\ProjectFolders\YourProjectCode" instead of the correct path without the leading space. As a result, Test-Path returns $false, and the script skips the group creation logic entirely.
Fix this by removing the extra space:
$ProjectFolder = "$Folder\$ProjectName"
2. Additional Troubleshooting & Optimizations
Even after fixing the path, here are some checks to ensure everything works as expected:
- Verify Verbose Output: You added the
-Verboseflag toNew-ADGroup, but if you don’t see any verbose logs when running the function, it means theifblock never ran. Call your function with-Verbose(e.g.,AD -ProjectCode "PROJ123" -Verbose) to confirm this. - Validate the AD OU Path: Double-check that
OU=Groups, OU=Test, OU=Ohio, OU=NA, DC=aws, DC=example, DC=comactually exists in your AD environment. Typos in OU names or domain components will silently fail (or throw errors if you add proper error handling). - Add Error Handling & Feedback: Right now, you have no indication if the folder check fails. Add an
elseblock to clarify what’s happening:if(Test-Path -Path $ProjectFolder){ New-ADGroup -Name $adminName -GroupScope DomainLocal -DisplayName $adminName -Path "OU=Groups, OU=Test, OU=Ohio, OU=NA, DC=aws, DC=example, DC=com" -Verbose } else { Write-Warning "Project folder $ProjectFolder doesn't exist - skipping AD group creation" } - Check Permissions: Ensure the account running the script has permissions to create groups in the target OU. While missing permissions usually throws an error, it’s worth testing manually by running
New-ADGroupdirectly with the same path to confirm.
Fixed Full Script Example
Function AD{ Param ( [Parameter (Mandatory=$true)] [STRING] $ProjectCode ) # Set up folder path $ProjectName = $ProjectCode $Folder = "C:\FunctionOutputs\ProjectFolders" $ProjectFolder = "$Folder\$ProjectName" # Fixed leading space issue # Define AD group name $adminName = "AB_$ProjectName_CDE_ADMIN_LCL" Write-Host "Target AD group: $adminName" # Check folder existence and create group if(Test-Path -Path $ProjectFolder){ Write-Host "Project folder found - creating AD group..." New-ADGroup -Name $adminName -GroupScope DomainLocal -DisplayName $adminName -Path "OU=Groups, OU=Test, OU=Ohio, OU=NA, DC=aws, DC=example, DC=com" -Verbose } else { Write-Warning "Project folder $ProjectFolder does NOT exist - AD group creation skipped" } }
内容的提问来源于stack exchange,提问作者jgtrz
相关产品推荐
相关产品推荐

