咨询:PowerShell中Get-ADComputer的Windows 7计算机LDAP查询
Great question! Let’s start by breaking down your existing LDAP filter to make sure we’re on the same page, then walk through common tweaks and expansions to adapt it to different scenarios.
First, your current filter (decoded from the HTML entity & to the actual LDAP & operator) looks like this:
(& (operatingSystem=*Windows 7*) (name=*-*) (!name=V7-*) (!name=*-none) (!name=*-oncall) (!name=*-blackbaud) (!name=sc-win7-1) (!name=ut-swclient-01))
In plain terms: Get all computers where the OS contains "Windows 7", the name includes a hyphen, and the name does NOT match any of the excluded patterns/specific devices.
Now let’s cover how to adjust this for different business needs:
1. Expand or Narrow the Operating System Scope
If you need to include more OS versions (or restrict to a specific SKU), modify the operatingSystem clause:
- Include both Windows 7 and Windows 10: Use an OR operator (
|) to group OS conditions(& (|(operatingSystem=*Windows 7*)(operatingSystem=*Windows 10*)) (name=*-*) (!name=V7-*) ... ) - Target a specific Windows 7 edition (more efficient than wildcard matches):
(& (operatingSystem=Windows 7 Enterprise) (name=*-*) (!name=V7-*) ... )
2. Adjust Name Matching Rules
Tweak the name conditions to fit your device naming conventions:
- Remove the hyphen requirement: Delete the
(name=*-*)clause entirely if you want all Windows 7 machines (regardless of name format), minus your excluded devices. - Match specific name prefixes/suffixes: Replace
(name=*-*)with something like:- Only devices starting with
DESK-:(name=DESK-*) - Devices starting with
DESK-ORLAP-:(|(name=DESK-*)(name=LAP-*)) - Devices ending with
-prod:(name=*-prod)
- Only devices starting with
3. Batch-Manage Excluded Devices
If your exclusion list grows long, manually adding !name= clauses gets messy. Generate the filter dynamically with PowerShell instead:
# Define your excluded patterns/devices in an array $excludedNames = @("V7-*", "*-none", "*-oncall", "*-blackbaud", "sc-win7-1", "ut-swclient-01") # Convert the array to LDAP exclusion clauses $excludeFilters = $excludedNames | ForEach-Object { "(!name=$_)" } # Build the full filter $computersFilter = "(& (operatingSystem=*Windows 7*) (name=*-*) $($excludeFilters -join ''))"
Now you just need to update the $excludedNames array when you add/remove devices to exclude—no more editing the raw LDAP string.
4. Add Filters for Other Attributes
Incorporate additional AD computer properties to refine your results:
- Exclude inactive devices (e.g., no logon in 90 days):
# Convert a date to LDAP's file time format $inactiveCutoff = [DateTime]::Now.AddDays(-90).ToFileTime() $computersFilter = "(& (operatingSystem=*Windows 7*) (name=*-*) (!name=V7-*) ... (LastLogonDate>=$inactiveCutoff))" - Restrict to a specific OU: While you could add this to the LDAP filter, it’s more efficient to use the
Get-ADComputer-SearchBaseparameter instead:$computers = Get-ADComputer -LDAPFilter $computersFilter -SearchBase "OU=Workstations,DC=contoso,DC=com" -Property LastLogonDate
5. Change Logical Relationships
Switch between AND (&) and OR (|) operators to alter how conditions interact:
- Get Windows 7 machines OR devices with a specific name pattern:
(|(operatingSystem=*Windows 7*)(name=DESK-*)) - Get Windows 7 machines that are either in the "Prod" OU OR have a
-prodsuffix:
Combine LDAP filters with the-SearchBaseparameter, or use a more complex nested filter:(& (operatingSystem=*Windows 7*) (|(name=*-prod)(distinguishedName=*,OU=Prod,DC=contoso,DC=com)))
Quick LDAP Filter Best Practices
- Minimize wildcards where possible: Exact matches (like
operatingSystem=Windows 7) are faster because AD can use indexed attributes. - Test filters with a small result set first: Use
-ResultSetSize 10withGet-ADComputerto verify your filter works before pulling all devices. - Keep nested logic clean: Use parentheses to group related conditions so your filter stays readable.
内容的提问来源于stack exchange,提问作者Our Man in Bananas

