You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell在AD指定组织单元创建用户失败求助

在Active Directory指定OU(Ressource)中创建用户的解决方案

咱们先拆解一下你遇到的问题,然后一步步解决:

问题根源分析

  1. 未指定目标OU位置:你的第一个New-ADUser命令没有添加-Path参数,这会导致用户被创建到AD的默认用户容器(通常是CN=Users,DC=你的域,DC=com),而不是你想要的Ressource组织单元里。
  2. 错误使用Add-ADGroupMember:这个命令的作用是将已存在的用户/计算机添加到AD组里,完全不能用来创建新用户,所以这一步从逻辑上就错了。

正确的解决方案代码

首先,你需要先获取Ressource OU的完整LDAP路径(比如假设你的域是tes000t.com,OU路径就是OU=Ressource,DC=tes000t,DC=com,请根据你的实际域结构调整)。然后修正New-ADUser的参数,尤其是密码的处理(必须转换成安全字符串):

# 获取用户输入
$fullName = Read-Host "Enter your full name"
$givenName = Read-Host "Enter your first name"
$surName = Read-Host "Enter your last name"  # 把硬编码的姓氏改成动态输入,按需调整
$samAccountName = Read-Host "Enter the SAM account name"
$userPrincipalName = Read-Host "Enter the user principal name (e.g., user@domain.com)"
$pwdPlain = Read-Host "Enter the password" -AsSecureString  # 直接读取为安全字符串

# 定义目标OU的LDAP路径,请替换成你实际的Ressource OU路径
$targetOU = "OU=Ressource,DC=tes000t,DC=com"

# 创建用户并禁用账号
New-ADUser -Name $fullName `
           -GivenName $givenName `
           -Surname $surName `
           -SamAccountName $samAccountName `
           -UserPrincipalName $userPrincipalName `
           -Description "tes000tg" `
           -Office "lol" `
           -AccountPassword $pwdPlain `
           -Path $targetOU `  # 关键:指定要创建用户的OU
           -Enabled $false `  # 直接禁用,不需要后续管道,更直观
           -PassThru

关键参数说明

  • -Path:必须填写目标OU的完整LDAP路径,这是让用户创建到指定OU的核心参数。
  • -AccountPassword:必须传入SecureString类型的密码,使用Read-Host -AsSecureString可以直接获取安全字符串,避免明文风险。
  • -Enabled $false:直接设置账号禁用,比管道到Disable-ADAccount更简洁高效。

验证创建结果

执行代码后,你可以用以下命令检查用户是否在指定OU中:

Get-ADUser -Identity $samAccountName -Properties DistinguishedName | Select-Object DistinguishedName

输出的DistinguishedName里应该包含OU=Ressource,说明用户已经正确创建到目标OU了。

内容的提问来源于stack exchange,提问作者lol lol

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:46:40