编写域计算机移除再加入脚本,Add-Computer命令报错RPC Server不可用
My Scenario
I'm building a PowerShell script for my IT team to remotely remove a computer from our domain and rejoin it. Here's the script I've put together so far:
$Hostname = Read-Host "Please enter the computers hostname that you wish to remove and re-add to the domain" Remove-Computer -ComputerName "$Hostname" -UnjoinDomainCredential "DOMAIN\$env:USERNAME" -PassThru -Verbose -Restart Add-Computer -ComputerName "$Hostname" -LocalCredential "$Hostname\ukitadmin" -Credential "DOMAIN\$env:USERNAME" -DomainName "DOMAIN" -Force -Verbose -Restart
The $env:USERNAME variable uses the admin account I'm running PS ISE with. The Remove-Computer command works as expected, but when the script tries to run Add-Computer, I get the error: "RPC Server is Unavailable". I need help troubleshooting this issue.
Common Causes & Solutions
Let's walk through the most likely reasons for this error and how to fix them:
1. Timing Issue Post-Restart
When you run Remove-Computer with -Restart, the target machine reboots immediately. The Add-Computer command fires right after, but the target might not be fully booted or have critical services (like RPC) running yet—especially on slower hardware.
Fix: Add a wait loop to ensure the target is reachable and services are ready before attempting to rejoin:
$Hostname = Read-Host "Please enter the computers hostname that you wish to remove and re-add to the domain" # Remove from domain and trigger restart Remove-Computer -ComputerName "$Hostname" -UnjoinDomainCredential "DOMAIN\$env:USERNAME" -PassThru -Verbose -Restart # Wait for the computer to come back online Write-Verbose "Waiting for $Hostname to reboot..." do { Start-Sleep -Seconds 30 } until (Test-Connection -ComputerName $Hostname -Count 1 -Quiet -ErrorAction SilentlyContinue) # Add extra time for RPC and other services to initialize Start-Sleep -Seconds 60 # Proceed with domain join Add-Computer -ComputerName "$Hostname" -LocalCredential "$Hostname\ukitadmin" -Credential "DOMAIN\$env:USERNAME" -DomainName "DOMAIN" -Force -Verbose -Restart
2. Firewall Blocking RPC Ports
RPC communication relies on ports 135 (RPC endpoint mapper) plus dynamic ports being open between your machine and the target. If the target's firewall is blocking these ports, you'll get the "unavailable" error.
Fix: Enable necessary firewall rules on the target (run this before removing the computer from the domain):
Invoke-Command -ComputerName $Hostname -ScriptBlock { # Enable required firewall groups Enable-NetFirewallRule -DisplayGroup "File and Printer Sharing" Enable-NetFirewallRule -DisplayGroup "Remote Administration" } -Credential "DOMAIN\$env:USERNAME"
3. Invalid Local Credentials
Double-check that the ukitadmin local account exists on the target machine and has administrative privileges. If the account is missing or lacks permissions, Add-Computer can't authenticate to the target to start the domain join process.
Fix: Verify the local account status pre-unjoin:
Invoke-Command -ComputerName $Hostname -ScriptBlock { # Check if the account exists net user ukitadmin # Confirm it's in the local admins group net localgroup administrators ukitadmin /check } -Credential "DOMAIN\$env:USERNAME"
4. DNS Resolution Failures
If your machine can't resolve the target hostname to its correct IP address, RPC communication will break.
Fix: Validate DNS resolution with:
Resolve-DnsName $Hostname
If the result is incorrect or missing, flush your local DNS cache with ipconfig /flushdns or ensure the target is properly registered in your DNS server.
Final Tip
Keep in mind that after removing a computer from the domain, AD replication can take a few minutes to propagate the change. The extra delay in the script helps account for this as well.
内容的提问来源于stack exchange,提问作者Brendan

