AD用户PowerShell脚本输入提示重复问题排查请求
问题原因分析与修复方案
核心问题:属性匹配逻辑错误
脚本的验证逻辑存在根本性错误:它提取了AD用户的name属性(即用户显示名),却将其与用户输入的SamAccountName(登录用户名)做相等对比。当用户的显示名与登录用户名不一致时,验证就会失败,导致重复出现输入提示。
举个实际例子:
- 用户输入的登录名是
lisa.smith(对应AD的SamAccountName属性) - 该用户在AD中的显示名(
name属性)是Lisa Smith - 此时
$look的值是Lisa Smith,和输入的lisa.smith完全不相等,验证无法通过。
脚本错误点拆解
看这段关键代码:
$look = ($search.FindAll() | Select-Object -ExpandProperty Properties).name # 后续判断逻辑:$look -eq $domaincreds
$domaincreds是用户输入的登录用户名(SamAccountName),但$look取的是用户的显示名(name属性)。域环境中这两个属性没有强制一致的要求,很多用户的显示名和登录名都是不同的,这就直接导致部分用户验证失败。
修复方案
有两种简单的修复方式:
方案1:直接验证用户是否存在(推荐)
不需要对比属性,直接判断搜索结果是否存在用户即可:
do{ Write-Host -NoNewline "Please enter your username and press enter: " -BackgroundColor Gray -ForegroundColor DarkBlue $domaincreds = Read-Host $search = [adsisearcher]"(&(objectCategory=person)(objectClass=User)(SamAccountname=$domaincreds))" $userExists = $search.FindAll().Count -gt 0 if(!$userExists) {write-host "Name doesn't exist! Please try again."} } until($userExists)
方案2:匹配正确的属性
如果一定要保留属性对比逻辑,应该对比SamAccountName而非name:
do{ Write-Host -NoNewline "Please enter your username and press enter: " -BackgroundColor Gray -ForegroundColor DarkBlue $domaincreds = Read-Host $search = [adsisearcher]"(&(objectCategory=person)(objectClass=User)(SamAccountname=$domaincreds))" $look = ($search.FindAll() | Select-Object -ExpandProperty Properties).samaccountname if(!($look)) {write-host "Name doesn't exist! Please try again."} } until($look -eq $domaincreds)
内容的提问来源于stack exchange,提问作者LILDASHIEGRINGO
相关产品推荐
相关产品推荐

