通过C#删除Active Directory中的用户

时间:2011-09-26 22:34:08

标签: c#

我正在尝试通过C#删除Active Directory中的用户。当我尝试运行以下代码时,出现错误。

错误讯息:

A local error has occurred

代码:

DirectoryEntry ent = new DirectoryEntry("LDAP://192.168.1.99/OU=FIRMA");
    ent.Username = "idm\administrator";
    ent.Password = "123123QQ";
    DirectorySearcher dsrc = new DirectorySearcher(ent);
    dsrc.Filter = string.Format("(&(objectCategory=user)(SAMAccountName=adKullaniciadi))");
    DirectoryEntry silsunuya = ent.Children.Find("CN=adKullaniciadi","objectClass=person");
    ent.Children.Remove(silsunuya);
    ent.Close();
    silsunuya.Close();
    dsrc.Dispose();

1 个答案:

答案 0 :(得分:1)

我有一个运行本地的ASP.Net网站,我们的IT团队用它来删除AD帐户,它似乎工作正常。我记得当我开发这个应用程序时,我必须处理很多细微差别,这可能会让人很难弄清楚AD发生了什么。这是我正在使用的代码(在VB.Net中):

Public Shared Function GetUser(ByVal username As String) As DirectoryEntry
    If String.IsNullOrEmpty(username) Then Return Nothing

    Dim path As String = ConfigurationManager.ConnectionStrings("ADConnectionString").ConnectionString
    Dim ds As New DirectorySearcher(path)

    ds.Filter = "(&(objectClass=user)(sAMAccountName=" + username + "))"
    ds.PropertiesToLoad.Add("sAMAccountName")         ' username
    ds.PropertiesToLoad.Add("mail")         ' e-mail address
    ds.PropertiesToLoad.Add("description")  ' Bureau ID
    ds.PropertiesToLoad.Add("company")      ' company name
    ds.PropertiesToLoad.Add("givenname")    ' first name
    ds.PropertiesToLoad.Add("sn")           ' last name
    ds.PropertiesToLoad.Add("name")         ' client name
    ds.PropertiesToLoad.Add("cn")           ' common name
    ds.PropertiesToLoad.Add("dn")           ' display name
    ds.PropertiesToLoad.Add("pwdLastSet")
    ds.SearchScope = SearchScope.Subtree
    Dim results As SearchResult = ds.FindOne

    If results IsNot Nothing Then
        Return New DirectoryEntry(results.Path)
    Else
        Return Nothing
    End If
End Function

Public Shared Sub DeleteUser(ByVal username As String, Optional ByVal useImpersonation As Boolean = False)
    Dim user As DirectoryEntry = GetUser(username)
    Dim ou As DirectoryEntry = user.Parent
    ou.Children.Remove(user)
    ou.CommitChanges()
End Sub

查看您的代码,以下是一些想法:

  1. 尝试使用dsrc.PropertiesToLoad.Add(“sAMAccountName”)
  2. 尝试添加对ent.CommitChanges()
  3. 的调用
  4. 您是否可以使用命令行AD查询工具验证路径和凭据是否正确?
  5. 您能具体确定错误发生在哪一行吗?