You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨多域及子域获取AD用户所属组的问题求助

跨多域及子域获取AD用户所属组的问题求助

我现在需要获取某个用户在所有域和子域中的所有所属组,目前的环境是这样的:

  • Forest 1
    • domain1.local
    • sub.domain1.local
  • Forest 2
    • domain2.local

这个用户位于domain1.local,我已经成功获取到了他在domain1.local和domain2.local中的所有组,但就是拿不到sub.domain1.local里的组。

我目前写的代码是这样的:

$domain1user = Get-ADUser -Server DC.domain1.local -Filter "Name -like 'John Doe'"
$domain1groups = Get-ADUser -Identity $domain1user -Server DC.domain1.local -Credential $myCreds -Properties MemberOf | Select-Object -ExpandProperty MemberOf

$domain2user = "CN=$($domain1user.SID.Value),CN=ForeignSecurityPrincipals,DC=domain2,DC=local"
$domain2groups = (Get-ADObject -Identity $domain2user -Server DC.domain2.local -Credential $myCreds -Properties MemberOf).MemberOf

我尝试用类似的方法获取子域的组,但还没搞定,比如这样:

$subdomaingroups = (Get-A...

有没有大佬能帮忙看看怎么解决这个问题?

备注:内容来源于stack exchange,提问作者IngoMarlboro

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.17 08:58:02