如何用Set-ADObject批量修改ADLS中自定义字段ont-configvalue?
Got it, let's work through this problem. You’ve got the query part sorted with Get-ADObject, but hitting a wall when trying to update that custom ont-configvalue attribute with Set-ADObject—plus you need a scalable way to handle around 20 different parameter-value pairs. Here’s how to fix this and build a reusable solution:
First: Fix the Single Update Issue
The most common reason Set-ADObject fails here is either incorrect syntax for referencing the attribute, not targeting the right object, or permission/attribute read-only constraints. Let’s start with a working single-update script:
# 1. Locate the exact object you want to update $targetObject = Get-ADObject -Server 'localhost:389' ` -Filter {(name -like "name") -and (ObjectClass -eq "ont-configparameter")} ` -SearchBase 'CN=Bob,O=Bob1' ` -Properties "ont-configvalue" | Where-Object { $_.ont-configvalue -eq ".bob.bob.com" } # 2. Update if the object exists if ($targetObject) { try { Set-ADObject -Server 'localhost:389' ` -Identity $targetObject ` -Replace @{ "ont-configvalue" = ".bob.bob.co.uk" } ` -ErrorAction Stop Write-Host "Successfully updated ont-configvalue for: $($targetObject.DistinguishedName)" -ForegroundColor Green } catch { Write-Error "Update failed: $_" } } else { Write-Warning "No matching object found with the specified criteria" }
Why This Works:
- We’re directly passing the object returned by
Get-ADObjecttoSet-ADObjectvia-Identity, so there’s no ambiguity about which object to modify. - The
-Replaceparameter uses a hashtable to specify the attribute and its new value—this is the correct syntax for modifying single-valued attributes likeont-configvalue.
Build a Scalable Solution for 20+ Parameters
To handle multiple updates efficiently, you can use either a hashtable (for hardcoded values) or a CSV file (for easier maintenance).
Option 1: Hashtable for Hardcoded Updates
This is great if your parameter list doesn’t change often:
# Define all your parameter-value pairs here $configUpdates = @{ "name1" = ".bob.bob.co.uk" "name2" = ".alice.alice.com" "name3" = ".charlie.charlie.net" # Add up to your 20+ entries here } # Loop through each update foreach ($update in $configUpdates.GetEnumerator()) { $targetName = $update.Key $newValue = $update.Value try { # Find the target object $targetObject = Get-ADObject -Server 'localhost:389' ` -Filter {(name -like $targetName) -and (ObjectClass -eq "ont-configparameter")} ` -SearchBase 'CN=Bob,O=Bob1' ` -Properties "ont-configvalue" ` -ErrorAction Stop if ($targetObject) { # Perform the update Set-ADObject -Server 'localhost:389' ` -Identity $targetObject ` -Replace @{ "ont-configvalue" = $newValue } ` -ErrorAction Stop Write-Host "Updated '$targetName' to: $newValue" -ForegroundColor Green } else { Write-Warning "No object found for name: '$targetName'" } } catch { Write-Error "Failed to process '$targetName': $_" } }
Option 2: CSV File for Easy Maintenance
If you need to update the parameter list frequently, a CSV file is more manageable. Create a file named ad-config-updates.csv with this structure:
Name,NewConfigValue name1,.bob.bob.co.uk name2,.alice.alice.com name3,.charlie.charlie.net
Then use this script to read and process it:
# Import the CSV file $updateList = Import-Csv -Path "C:\path\to\ad-config-updates.csv" # Process each entry foreach ($item in $updateList) { $targetName = $item.Name $newValue = $item.NewConfigValue try { $targetObject = Get-ADObject -Server 'localhost:389' ` -Filter {(name -like $targetName) -and (ObjectClass -eq "ont-configparameter")} ` -SearchBase 'CN=Bob,O=Bob1' ` -Properties "ont-configvalue" ` -ErrorAction Stop if ($targetObject) { Set-ADObject -Server 'localhost:389' ` -Identity $targetObject ` -Replace @{ "ont-configvalue" = $newValue } ` -ErrorAction Stop Write-Host "Successfully updated: $targetName -> $newValue" -ForegroundColor Green } else { Write-Warning "Skipping '$targetName': No matching object found" } } catch { Write-Error "Error processing '$targetName': $_" } }
Critical Checks to Avoid Failures
- Permissions: Ensure the account running the script has Write permission on the
ont-configvalueattribute for the target objects. - Attribute Read-Only Status: Verify
ont-configvalueisn’t a read-only attribute. Run this to check:
IfGet-ADObject -SearchBase (Get-ADRootDSE).schemaNamingContext ` -Filter {name -eq "ont-configvalue"} ` -Properties isSingleValued, systemFlagssystemFlagsincludes the value16, the attribute is read-only and can’t be modified. - Filter Accuracy: Double-check your
-Filterand-SearchBaseto make sure you’re targeting the correct objects—small typos here will cause no matches.
内容的提问来源于stack exchange,提问作者Richard Dakin

