可以使用 PowerShell 或舊版 dsquery 命令從命令列查詢 Active Directory。
PowerShell Active Directory 命令
列出所有使用者:
命令
Get-ADUser -Filter *
查詢特定使用者:
命令
Get-ADUser -Identity "username"
按姓名搜尋使用者:
命令
Get-ADUser -Filter "Name -like '*John*'"
列出所有計算機:
命令
Get-ADComputer -Filter *
列出所有組:
命令
Get-ADGroup -Filter *
獲取域名資訊:
命令
Get-ADDomain
獲取域控制器:
命令
Get-ADDomainController -Filter *
啟用PowerShell AD模組
如果 Get-ADUser 不起作用,請啟用該模組:
Windows 伺服器:
命令
Import-Module ActiveDirectory
Windows 10/11: 從“設定”>“應用程式”>“可選功能”安裝 RSAT(遠端伺服器管理工具)。
然後執行:
命令
Import-Module ActiveDirectory
舊版 DSQUERY 命令
在加入域的計算機上無需 PowerShell 模組即可工作。
查詢所有使用者:
命令
dsquery user
按名稱查詢使用者:
命令
dsquery user -name "John*"
查詢所有計算機:
命令
dsquery computer
查詢所有組:
命令
dsquery group
查詢禁用帳戶:
命令
dsquery user -disabled
查詢不活動的計算機(90 天):
命令
dsquery computer -inactive 12
12 周 = 大約 90 天。
獲取詳細的使用者資訊
PowerShell - 顯示所有屬性:
命令
Get-ADUser -Identity "username" -Properties *
DSGET(舊版):
命令
dsquery user -name "username" | dsget user -display -email -mobile
查詢使用者的組成員資格
PowerShell:
命令
Get-ADPrincipalGroupMembership -Identity "username"
DSGET:
命令
dsget user "CN=Username,OU=Users,DC=domain,DC=com" -memberof
查詢群組成員
PowerShell:
命令
Get-ADGroupMember -Identity "GroupName"
DSGET:
命令
dsget group "CN=GroupName,OU=Groups,DC=domain,DC=com" -members
檢查使用者是否被鎖定
PowerShell:
命令
Get-ADUser -Identity "username" -Properties LockedOut | Select-Object Name,LockedOut
解鎖使用者:
命令
Unlock-ADAccount -Identity "username"
重置使用者密碼
命令
Set-ADAccountPassword -Identity "username" -Reset -NewPassword (ConvertTo-SecureString -AsPlainText "NewPassword123!" -Force)
下次登入時強制更改密碼:
命令
Set-ADUser -Identity "username" -ChangePasswordAtLogon $true
搜尋計算機
姓名:
命令
Get-ADComputer -Filter "Name -like '*DESKTOP*'"
按作業系統:
命令
Get-ADComputer -Filter "OperatingSystem -like '*Windows 11*'" -Properties OperatingSystem
將結果匯出到 CSV
PowerShell:
命令
Get-ADUser -Filter * -Properties DisplayName,EmailAddress | Export-Csv users.csv -NoTypeInformation
建立包含使用者資料的 CSV 檔案。
常用濾鏡
過去 30 天內建立的使用者:
命令
$date = (Get-Date).AddDays(-30)
Get-ADUser -Filter "Created -gt '$date'" -Properties Created
使用者從未登入:
命令
Get-ADUser -Filter "LastLogonDate -notlike '*'" -Properties LastLogonDate
90 天未登入的計算機:
命令
$date = (Get-Date).AddDays(-90)
Get-ADComputer -Filter "LastLogonDate -lt '$date'" -Properties LastLogonDate
故障排除
“Get-ADUser 無法識別”: 匯入ActiveDirectory模組或安裝RSAT。
“無法聯絡伺服器”: 不在域網路或無法訪問域控制器上。
“訪問被拒絕”: 需要域管理員或適當的 AD 許可權。
DSQUERY 不返回任何內容: 檢查語法,確保加入域,驗證網路連線。
底線
PowerShell(現代):
命令
Get-ADUser -Filter * | Find users
Get-ADComputer -Filter * | Find computers
Get-ADGroup -Filter * | Find groups
DSQUERY(舊版):
命令
dsquery user | Find users
dsquery computer | Find computers
dsquery group | Find groups
PowerShell 更強大,但需要 ActiveDirectory 模組。 DSQUERY 可在加入域的計算機上執行,無需額外設定。
兩者都需要域網路連線和適當的許可權。