You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Set-ADObject批量修改ADLS中自定义字段ont-configvalue?

Fixing AD Custom Attribute Updates with PowerShell (Scalable for 20+ Parameters)

Got it, let's work through this problem. You’ve got the query part sorted with Get-ADObject, but hitting a wall when trying to update that custom ont-configvalue attribute with Set-ADObject—plus you need a scalable way to handle around 20 different parameter-value pairs. Here’s how to fix this and build a reusable solution:

First: Fix the Single Update Issue

The most common reason Set-ADObject fails here is either incorrect syntax for referencing the attribute, not targeting the right object, or permission/attribute read-only constraints. Let’s start with a working single-update script:

# 1. Locate the exact object you want to update
$targetObject = Get-ADObject -Server 'localhost:389' `
    -Filter {(name -like "name") -and (ObjectClass -eq "ont-configparameter")} `
    -SearchBase 'CN=Bob,O=Bob1' `
    -Properties "ont-configvalue" | 
    Where-Object { $_.ont-configvalue -eq ".bob.bob.com" }

# 2. Update if the object exists
if ($targetObject) {
    try {
        Set-ADObject -Server 'localhost:389' `
            -Identity $targetObject `
            -Replace @{ "ont-configvalue" = ".bob.bob.co.uk" } `
            -ErrorAction Stop
        Write-Host "Successfully updated ont-configvalue for: $($targetObject.DistinguishedName)" -ForegroundColor Green
    } catch {
        Write-Error "Update failed: $_"
    }
} else {
    Write-Warning "No matching object found with the specified criteria"
}

Why This Works:

  • We’re directly passing the object returned by Get-ADObject to Set-ADObject via -Identity, so there’s no ambiguity about which object to modify.
  • The -Replace parameter uses a hashtable to specify the attribute and its new value—this is the correct syntax for modifying single-valued attributes like ont-configvalue.

Build a Scalable Solution for 20+ Parameters

To handle multiple updates efficiently, you can use either a hashtable (for hardcoded values) or a CSV file (for easier maintenance).

Option 1: Hashtable for Hardcoded Updates

This is great if your parameter list doesn’t change often:

# Define all your parameter-value pairs here
$configUpdates = @{
    "name1" = ".bob.bob.co.uk"
    "name2" = ".alice.alice.com"
    "name3" = ".charlie.charlie.net"
    # Add up to your 20+ entries here
}

# Loop through each update
foreach ($update in $configUpdates.GetEnumerator()) {
    $targetName = $update.Key
    $newValue = $update.Value

    try {
        # Find the target object
        $targetObject = Get-ADObject -Server 'localhost:389' `
            -Filter {(name -like $targetName) -and (ObjectClass -eq "ont-configparameter")} `
            -SearchBase 'CN=Bob,O=Bob1' `
            -Properties "ont-configvalue" `
            -ErrorAction Stop

        if ($targetObject) {
            # Perform the update
            Set-ADObject -Server 'localhost:389' `
                -Identity $targetObject `
                -Replace @{ "ont-configvalue" = $newValue } `
                -ErrorAction Stop
            Write-Host "Updated '$targetName' to: $newValue" -ForegroundColor Green
        } else {
            Write-Warning "No object found for name: '$targetName'"
        }
    } catch {
        Write-Error "Failed to process '$targetName': $_"
    }
}

Option 2: CSV File for Easy Maintenance

If you need to update the parameter list frequently, a CSV file is more manageable. Create a file named ad-config-updates.csv with this structure:

Name,NewConfigValue
name1,.bob.bob.co.uk
name2,.alice.alice.com
name3,.charlie.charlie.net

Then use this script to read and process it:

# Import the CSV file
$updateList = Import-Csv -Path "C:\path\to\ad-config-updates.csv"

# Process each entry
foreach ($item in $updateList) {
    $targetName = $item.Name
    $newValue = $item.NewConfigValue

    try {
        $targetObject = Get-ADObject -Server 'localhost:389' `
            -Filter {(name -like $targetName) -and (ObjectClass -eq "ont-configparameter")} `
            -SearchBase 'CN=Bob,O=Bob1' `
            -Properties "ont-configvalue" `
            -ErrorAction Stop

        if ($targetObject) {
            Set-ADObject -Server 'localhost:389' `
                -Identity $targetObject `
                -Replace @{ "ont-configvalue" = $newValue } `
                -ErrorAction Stop
            Write-Host "Successfully updated: $targetName -> $newValue" -ForegroundColor Green
        } else {
            Write-Warning "Skipping '$targetName': No matching object found"
        }
    } catch {
        Write-Error "Error processing '$targetName': $_"
    }
}

Critical Checks to Avoid Failures

  1. Permissions: Ensure the account running the script has Write permission on the ont-configvalue attribute for the target objects.
  2. Attribute Read-Only Status: Verify ont-configvalue isn’t a read-only attribute. Run this to check:
    Get-ADObject -SearchBase (Get-ADRootDSE).schemaNamingContext `
        -Filter {name -eq "ont-configvalue"} `
        -Properties isSingleValued, systemFlags
    
    If systemFlags includes the value 16, the attribute is read-only and can’t be modified.
  3. Filter Accuracy: Double-check your -Filter and -SearchBase to make sure you’re targeting the correct objects—small typos here will cause no matches.

内容的提问来源于stack exchange,提问作者Richard Dakin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 06:53:44