FIM PowerShell脚本导出注册用户CSV仅显示自身账号问题求助
Let's break down why your script is only returning your display name and fix it step by step.
First, Spot Obvious Script Issues
Looking at your code, there are a few syntax and logic problems that could be causing unexpected results:
1. Malformed URI Variable
Your URI variable has an extra single quote and trailing space, which can cause silent failures (made worse by your -ErrorAction SilentlyContinue setting):
set-variable -name URI -value "http://localhost:5725/resourcemanagementservice' " -option constant
Fix it to a valid, clean URI:
Set-Variable -Name URI -Value "http://localhost:5725/resourcemanagementservice" -Option Constant
2. Inconsistent Variable Casing
You initialize [array]$users = $null but later use $Users += $ResetPass (uppercase "U"). While PowerShell is mostly case-insensitive, this can lead to unexpected behavior in strict modes. Stick to consistent casing:
[array]$users = $null foreach($Object in $curObject) { # ... your existing code ... $users += $ResetPass }
3. Hidden Errors from -ErrorAction SilentlyContinue
Suppressing errors means you won't see if Export-FIMConfig is failing to retrieve all users. Remove this parameter temporarily to expose underlying issues:
$curObjectWFD = Export-FIMConfig -Uri $URI –OnlyBaseResources -CustomConfig ($WFDFilter) -ErrorVariable Err $curObject = Export-FIMConfig -Uri $URI –OnlyBaseResources -CustomConfig ($Filter) -ErrorVariable Err
Next, Check Permissions (Most Likely Root Cause)
The #1 reason for only seeing your own user is insufficient FIM Service permissions:
- The account running the script needs Read access to all
Personresources in FIM. - It also needs permission to read the
WorkflowDefinitionobject for the Password Reset AuthN Workflow. - Verify this in the FIM Portal: Go to Administration > Set Resource Security Permissions, then check your account's permissions on the Person resource type.
Verify Filter Logic
Let's confirm your filter is correctly targeting registered users:
- First, validate you're getting the correct workflow ObjectID. Run this standalone snippet:
Add-PSSnapin FIMAutomation $URI = "http://localhost:5725/resourcemanagementservice" $WFDFilter = "/WorkflowDefinition[DisplayName='Password Reset AuthN Workflow']" $curObjectWFD = Export-FIMConfig -Uri $URI –OnlyBaseResources -CustomConfig $WFDFilter $WFDObjectID = (($curObjectWFD.ResourceManagementObject.ResourceManagementAttributes | Where-Object {$_.AttributeName -eq "ObjectID"}).value).split(":")[2] Write-Host "Workflow ObjectID: $WFDObjectID"
Ensure this returns a valid GUID (not empty or null). If it's empty, double-check the workflow display name in FIM (it must match exactly).
- Test the Person filter directly to see how many users it returns:
$Filter = "/Person[AuthNWFRegistered = '$WFDObjectID']" $curObject = Export-FIMConfig -Uri $URI –OnlyBaseResources -CustomConfig $Filter Write-Host "Number of users returned: $($curObject.Count)"
If this returns 1, either only you are registered for the workflow, your filter is incorrect, or permissions are blocking access to other users.
Cleaned-Up, Fixed Script
Here's the revised script with syntax fixes, error checking, and clearer logic:
# Set valid constants Set-Variable -Name URI -Value "http://localhost:5725/resourcemanagementservice" -Option Constant Set-Variable -Name CSV -Value "RegistredResetPassUsers.csv" -Option Constant # Clear existing user array Clear-Variable -Name users -ErrorAction SilentlyContinue # Load FIMAutomation snapin if missing If (-not (Get-PSSnapin -Name FIMAutomation -ErrorAction SilentlyContinue)) { Add-PSSnapin FIMAutomation } # Retrieve Password Reset AuthN Workflow ObjectID $WFDFilter = "/WorkflowDefinition[DisplayName='Password Reset AuthN Workflow']" $curObjectWFD = Export-FIMConfig -Uri $URI –OnlyBaseResources -CustomConfig $WFDFilter -ErrorVariable Err if ($Err) { Write-Error "Failed to fetch workflow definition: $Err" exit 1 } $WFDObjectID = (($curObjectWFD.ResourceManagementObject.ResourceManagementAttributes | Where-Object {$_.AttributeName -eq "ObjectID"}).value).split(":")[2] if (-not $WFDObjectID) { Write-Error "Could not get valid ObjectID for the workflow" exit 1 } # Fetch all users registered for the workflow $Filter = "/Person[AuthNWFRegistered = '$WFDObjectID']" $curObject = Export-FIMConfig -Uri $URI –OnlyBaseResources -CustomConfig $Filter -ErrorVariable Err if ($Err) { Write-Error "Failed to retrieve users: $Err" exit 1 } Write-Host "Found $($curObject.Count) users registered for password reset" # Build and export user list [array]$users = @() foreach($Object in $curObject) { $UserDisplayName = ($Object.ResourceManagementObject.ResourceManagementAttributes | Where-Object {$_.AttributeName -eq "DisplayName"}).Value $ResetPass = [PSCustomObject]@{ DisplayName = $UserDisplayName } $users += $ResetPass } $users | Export-Csv -Path $CSV -NoTypeInformation Write-Host "Successfully exported results to $CSV"
Final Checks
- Run the script with an account that has full read permissions on FIM Person objects.
- Check the console output for error messages or the user count to confirm progress.
- If the count is still 1, verify in the FIM Portal that other users have completed the self-service password reset registration process.
内容的提问来源于stack exchange,提问作者Moujinn

