可以使用 PowerShell 或舊版 dsquery 命令從命令列查詢 Active Directory。

PowerShell Active Directory 命令

列出所有使用者:

命令
Get-ADUser -Filter *

查詢特定使用者:

命令
Get-ADUser -Identity "username"

按姓名搜尋使用者:

命令
Get-ADUser -Filter "Name -like '*John*'"

列出所有計算機:

命令
Get-ADComputer -Filter *

列出所有組:

命令
Get-ADGroup -Filter *

獲取域名資訊:

命令
Get-ADDomain

獲取域控制器:

命令
Get-ADDomainController -Filter *

啟用PowerShell AD模組

如果 Get-ADUser 不起作用,請啟用該模組:

Windows 伺服器:

命令
Import-Module ActiveDirectory

Windows 10/11: 從“設定”>“應用程式”>“可選功能”安裝 RSAT(遠端伺服器管理工具)。

然後執行:

命令
Import-Module ActiveDirectory

舊版 DSQUERY 命令

在加入域的計算機上無需 PowerShell 模組即可工作。

查詢所有使用者:

命令
dsquery user

按名稱查詢使用者:

命令
dsquery user -name "John*"

查詢所有計算機:

命令
dsquery computer

查詢所有組:

命令
dsquery group

查詢禁用帳戶:

命令
dsquery user -disabled

查詢不活動的計算機(90 天):

命令
dsquery computer -inactive 12

12 周 = 大約 90 天。

獲取詳細的使用者資訊

PowerShell - 顯示所有屬性:

命令
Get-ADUser -Identity "username" -Properties *

DSGET(舊版):

命令
dsquery user -name "username" | dsget user -display -email -mobile

查詢使用者的組成員資格

PowerShell:

命令
Get-ADPrincipalGroupMembership -Identity "username"

DSGET:

命令
dsget user "CN=Username,OU=Users,DC=domain,DC=com" -memberof

查詢群組成員

PowerShell:

命令
Get-ADGroupMember -Identity "GroupName"

DSGET:

命令
dsget group "CN=GroupName,OU=Groups,DC=domain,DC=com" -members

檢查使用者是否被鎖定

PowerShell:

命令
Get-ADUser -Identity "username" -Properties LockedOut | Select-Object Name,LockedOut

解鎖使用者:

命令
Unlock-ADAccount -Identity "username"

重置使用者密碼

命令
Set-ADAccountPassword -Identity "username" -Reset -NewPassword (ConvertTo-SecureString -AsPlainText "NewPassword123!" -Force)

下次登入時強制更改密碼:

命令
Set-ADUser -Identity "username" -ChangePasswordAtLogon $true

搜尋計算機

姓名:

命令
Get-ADComputer -Filter "Name -like '*DESKTOP*'"

按作業系統:

命令
Get-ADComputer -Filter "OperatingSystem -like '*Windows 11*'" -Properties OperatingSystem

將結果匯出到 CSV

PowerShell:

命令
Get-ADUser -Filter * -Properties DisplayName,EmailAddress | Export-Csv users.csv -NoTypeInformation

建立包含使用者資料的 CSV 檔案。

常用濾鏡

過去 30 天內建立的使用者:

命令
$date = (Get-Date).AddDays(-30)
Get-ADUser -Filter "Created -gt '$date'" -Properties Created

使用者從未登入:

命令
Get-ADUser -Filter "LastLogonDate -notlike '*'" -Properties LastLogonDate

90 天未登入的計算機:

命令
$date = (Get-Date).AddDays(-90)
Get-ADComputer -Filter "LastLogonDate -lt '$date'" -Properties LastLogonDate

故障排除

“Get-ADUser 無法識別”: 匯入ActiveDirectory模組或安裝RSAT。

“無法聯絡伺服器”: 不在域網路或無法訪問域控制器上。

“訪問被拒絕”: 需要域管理員或適當的 AD 許可權。

DSQUERY 不返回任何內容: 檢查語法,確保加入域,驗證網路連線。

底線

PowerShell(現代):

命令
Get-ADUser -Filter * | Find users
Get-ADComputer -Filter * | Find computers
Get-ADGroup -Filter * | Find groups

DSQUERY(舊版):

命令
dsquery user | Find users
dsquery computer | Find computers
dsquery group | Find groups

PowerShell 更強大,但需要 ActiveDirectory 模組。 DSQUERY 可在加入域的計算機上執行,​​無需額外設定。

兩者都需要域網路連線和適當的許可權。