如何获取TFS当前活跃用户列表?仅筛选绑定AD账户的用户
当然可以搞定这个需求!我给你分享两种实用的方法,帮你筛选出TFS里拥有有效AD账户的用户:
方法1:PowerShell脚本结合AD验证
这种方法适配所有TFS版本,通过tf identities导出用户列表后,用AD模块逐个验证账户有效性:
- 先导出TFS所有用户到临时文件:
tf identities /collection:http://你的TFS服务器地址:8080/tfs/你的项目集合名 > tfs_users.txt
- 编写PowerShell脚本读取文件并验证AD账户:
# 导入Active Directory模块(需要AD权限和RSAT工具支持) Import-Module ActiveDirectory # 读取导出的用户列表,过滤出域格式的账户(比如DOMAIN\username) $tfsUsers = Get-Content .\tfs_users.txt | Where-Object { $_ -match '^\w+\\\w+' } | ForEach-Object { # 提取纯净的账户名(去掉后面的描述、权限等冗余信息) $_.Split(' ')[0].Trim() } # 循环验证每个账户是否存在于AD中 foreach ($user in $tfsUsers) { $username = $user.Split('\')[1] $domain = $user.Split('\')[0] try { # 验证AD账户,可指定AD服务器地址优化查询 Get-ADUser -Identity $username -Server "$domain.com" -ErrorAction Stop Write-Host "✅ 有效AD账户:$user" } catch { Write-Host "❌ 无效/已删除AD账户:$user" } }
记得替换脚本里的TFS地址、项目集合名和AD服务器信息为你的实际环境内容。
方法2:TFS REST API + AD验证(适用于TFS 2017及以上)
如果你的TFS版本较新(2017+),用REST API获取用户列表会更灵活,还能直接拿到用户的显示名等额外信息:
$collectionUrl = "http://你的TFS服务器地址:8080/tfs/你的项目集合名" # 调用TFS REST API获取所有标识(用户/组) $identities = Invoke-RestMethod -Uri "$collectionUrl/_apis/identities?filter=General&api-version=4.1" -UseDefaultCredentials foreach ($identity in $identities.value) { # 只处理AD来源的用户(排除服务账户、本地账户等非AD身份) if ($identity.providerDisplayName -eq "Active Directory") { $username = $identity.uniqueName.Split('\')[1] try { Get-ADUser -Identity $username -ErrorAction Stop Write-Host "✅ 有效AD账户:$($identity.uniqueName)(姓名:$($identity.displayName))" } catch { Write-Host "❌ 无效/已删除AD账户:$($identity.uniqueName)(姓名:$($identity.displayName))" } } }
补充说明
你提到的那篇博客方法是基于用户登录日志筛选活跃登录过的用户,和你现在需要的“验证AD账户是否存在”是不同的需求。上面的两种方法更直接匹配你的目标——筛选出TFS中仍绑定有效AD账户的用户,不管他们是否近期登录过。
内容的提问来源于stack exchange,提问作者SRX
相关产品推荐
相关产品推荐

