You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Intune管理的Windows 11客户端PowerShell脚本读取用户邮箱地址失败问题

Intune管理的Windows 11客户端PowerShell脚本读取用户邮箱地址失败问题

看起来你遇到的核心问题是:原来的脚本依赖本地Active Directory的LDAP查询来获取用户邮箱,但Intune管理的Windows 11设备(尤其是纯Azure AD加入的设备)无法正常访问域控制器的LDAP服务,或者whoami /fqdn返回的格式在Azure AD环境下不兼容LDAP路径,导致脚本抛出连接错误。

下面给你几个适配Intune环境的解决方案,你可以根据自己的设备类型(纯Azure AD加入/混合AD加入)选择:

方案1:用Microsoft Graph PowerShell获取用户邮箱(推荐纯Azure AD设备)

这种方法直接从Azure AD获取用户信息,兼容性最好,但需要提前在客户端部署Microsoft Graph PowerShell模块。

修改后的脚本:

# 检查并安装Microsoft Graph用户模块(如果是Intune部署,建议提前预装)
if (-not (Get-Module -ListAvailable Microsoft.Graph.Users)) {
    Install-Module -Name Microsoft.Graph.Users -Force -Scope CurrentUser
}

# 用设备身份验证连接到Microsoft Graph(无需用户手动登录)
Connect-MgGraph -Scopes "User.Read" -UseDeviceAuthentication

# 获取当前用户的UPN,再通过Graph查询邮箱
$currentUserUpn = [System.Security.Principal.WindowsIdentity]::GetCurrent().Name.Split('\')[-1]
$userDetails = Get-MgUser -Filter "userPrincipalName eq '$currentUserUpn'" -Property Mail
$userEmail = $userDetails.Mail

# 原有逻辑保持不变
$exePath = "C:\Program Files\uniFLOW SmartClient\momsmartclnt.exe"
if (Test-Path $exePath) {
    if($userEmail -notLike "*stu.myDomain*") {
        Start-Process -FilePath $exePath
    }   
} else {
    Write-Host "File not found: $exePath"
}

方案2:通过WMI获取UPN替代邮箱(无需额外模块,快速适配)

如果你的企业环境中用户的UPN和邮箱地址一致,这个方案最省心,不需要安装任何额外模块:

$exePath = "C:\Program Files\uniFLOW SmartClient\momsmartclnt.exe"
# 获取当前用户的UPN
$currentUserUpn = (Get-CimInstance -ClassName Win32_ComputerSystem).UserName.Split('\')[-1]

# 原有判断逻辑保持,只是把邮箱换成UPN
if (Test-Path $exePath) {
    if($currentUserUpn -notLike "*stu.myDomain*") {
        Start-Process -FilePath $exePath
    }   
} else {
    Write-Host "File not found: $exePath"
}

方案3:用DirectoryServices.AccountManagement类(适合混合AD加入设备)

如果你的设备是同时加入本地AD和Azure AD的混合模式,这个方法比直接LDAP查询更稳定:

Add-Type -AssemblyName System.DirectoryServices.AccountManagement

$exePath = "C:\Program Files\uniFLOW SmartClient\momsmartclnt.exe"
# 初始化域上下文,查询当前用户信息
$domainContext = New-Object System.DirectoryServices.AccountManagement.PrincipalContext([System.DirectoryServices.AccountManagement.ContextType]::Domain)
$currentUser = [System.DirectoryServices.AccountManagement.UserPrincipal]::FindByIdentity($domainContext, [System.Security.Principal.WindowsIdentity]::GetCurrent().Name)
$userEmail = $currentUser.EmailAddress

# 原有逻辑保持不变
if (Test-Path $exePath) {
    if($userEmail -notLike "*stu.myDomain*") {
        Start-Process -FilePath $exePath
    }   
} else {
    Write-Host "File not found: $exePath"
}

额外说明

  • 纯Azure AD设备优先选方案1或方案2,方案3依赖本地AD的访问权限,可能无法正常工作。
  • 用方案1时,建议通过Intune的Win32应用部署提前预装Microsoft Graph模块,避免脚本运行时因权限不足安装失败。

备注:内容来源于stack exchange,提问作者Samuel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.16 12:15:29