You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ANR双等号(==)查询异常:为何返回两个AD用户结果?

Why does (anr==leon) return two AD users instead of one?

Let's break down why you're seeing two results instead of the single one you expected.

First, let's recap how the ANR (Ambiguous Name Resolution) filter works when using double equals (==):

You can force ANR to require an exact match on any of the attributes in the table by starting the value with the equal sign, "=" (so the filter has two equal signs)

The key point here is that ANR checks against a set of default attributes (not just one specific attribute you might be thinking of). By default, these attributes include givenName, sn (surname), name, sAMAccountName, displayName, and others depending on your AD environment.

Now let's look at your two users:

  1. CN=Leon1,CN=Users,DC=LH269,DC=com
    • Its sn (Surname) attribute is Leon — since AD attribute matching is case-insensitive, this counts as an exact match for leon.
  2. CN=Leon, Jennifer,CN=Users,DC=LH269,DC=com
    • Its sAMAccountName attribute is leon — this is a direct, case-insensitive exact match.

Since both users have at least one attribute in the ANR set that exactly matches leon, both get returned by your filter.

If you want to target only the specific user you expected, skip ANR and use a direct attribute filter instead. For example, to match the sAMAccountName exactly:

Get-ADUser -LDAPFilter '(sAMAccountName=leon)'

Or to match the full name attribute:

Get-ADUser -LDAPFilter '(name=Leon\, Jennifer)'

内容的提问来源于stack exchange,提问作者ilansch

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:46:30