Intune管理的Windows 11客户端PowerShell脚本读取用户邮箱地址失败问题
Intune管理的Windows 11客户端PowerShell脚本读取用户邮箱地址失败问题
看起来你遇到的核心问题是:原来的脚本依赖本地Active Directory的LDAP查询来获取用户邮箱,但Intune管理的Windows 11设备(尤其是纯Azure AD加入的设备)无法正常访问域控制器的LDAP服务,或者whoami /fqdn返回的格式在Azure AD环境下不兼容LDAP路径,导致脚本抛出连接错误。
下面给你几个适配Intune环境的解决方案,你可以根据自己的设备类型(纯Azure AD加入/混合AD加入)选择:
方案1:用Microsoft Graph PowerShell获取用户邮箱(推荐纯Azure AD设备)
这种方法直接从Azure AD获取用户信息,兼容性最好,但需要提前在客户端部署Microsoft Graph PowerShell模块。
修改后的脚本:
# 检查并安装Microsoft Graph用户模块(如果是Intune部署,建议提前预装) if (-not (Get-Module -ListAvailable Microsoft.Graph.Users)) { Install-Module -Name Microsoft.Graph.Users -Force -Scope CurrentUser } # 用设备身份验证连接到Microsoft Graph(无需用户手动登录) Connect-MgGraph -Scopes "User.Read" -UseDeviceAuthentication # 获取当前用户的UPN,再通过Graph查询邮箱 $currentUserUpn = [System.Security.Principal.WindowsIdentity]::GetCurrent().Name.Split('\')[-1] $userDetails = Get-MgUser -Filter "userPrincipalName eq '$currentUserUpn'" -Property Mail $userEmail = $userDetails.Mail # 原有逻辑保持不变 $exePath = "C:\Program Files\uniFLOW SmartClient\momsmartclnt.exe" if (Test-Path $exePath) { if($userEmail -notLike "*stu.myDomain*") { Start-Process -FilePath $exePath } } else { Write-Host "File not found: $exePath" }
方案2:通过WMI获取UPN替代邮箱(无需额外模块,快速适配)
如果你的企业环境中用户的UPN和邮箱地址一致,这个方案最省心,不需要安装任何额外模块:
$exePath = "C:\Program Files\uniFLOW SmartClient\momsmartclnt.exe" # 获取当前用户的UPN $currentUserUpn = (Get-CimInstance -ClassName Win32_ComputerSystem).UserName.Split('\')[-1] # 原有判断逻辑保持,只是把邮箱换成UPN if (Test-Path $exePath) { if($currentUserUpn -notLike "*stu.myDomain*") { Start-Process -FilePath $exePath } } else { Write-Host "File not found: $exePath" }
方案3:用DirectoryServices.AccountManagement类(适合混合AD加入设备)
如果你的设备是同时加入本地AD和Azure AD的混合模式,这个方法比直接LDAP查询更稳定:
Add-Type -AssemblyName System.DirectoryServices.AccountManagement $exePath = "C:\Program Files\uniFLOW SmartClient\momsmartclnt.exe" # 初始化域上下文,查询当前用户信息 $domainContext = New-Object System.DirectoryServices.AccountManagement.PrincipalContext([System.DirectoryServices.AccountManagement.ContextType]::Domain) $currentUser = [System.DirectoryServices.AccountManagement.UserPrincipal]::FindByIdentity($domainContext, [System.Security.Principal.WindowsIdentity]::GetCurrent().Name) $userEmail = $currentUser.EmailAddress # 原有逻辑保持不变 if (Test-Path $exePath) { if($userEmail -notLike "*stu.myDomain*") { Start-Process -FilePath $exePath } } else { Write-Host "File not found: $exePath" }
额外说明
- 纯Azure AD设备优先选方案1或方案2,方案3依赖本地AD的访问权限,可能无法正常工作。
- 用方案1时,建议通过Intune的Win32应用部署提前预装Microsoft Graph模块,避免脚本运行时因权限不足安装失败。
备注:内容来源于stack exchange,提问作者Samuel
相关产品推荐
相关产品推荐

