检查AD组是否存在

时间:2014-07-30 17:32:51

标签: ldap exists adgroup

尝试使用以下脚本检查AD组是否存在:

$Path = "LDAP://dc=cmc,dc=com"
$object = "CMC\QTKS-DEP-Admin-Temp"
$type = "Group"

$search = [System.DirectoryServices.DirectorySearcher]$Path
$search.Filter = "(&(name=$object)(objectCategory=$type))"
$Result = $search.FindOne()

IF( $Result -eq $null)
{
Write-Host "Group does not exist"
}
Else 
{   
Write-Host "Group exists"
}

我知道LDAP连接字符串或变量声明有问题。或者是其他东西。有人可以纠正。结果始终显示为"组不存在"即使它存在。

1 个答案:

答案 0 :(得分:0)

终于明白了:

$Search = New-Object DirectoryServices.DirectorySearcher
$Search.Filter = '(&(objectCategory=Group)(anr=CMC\QTKS-DEP-Admin-Temp))'
$Search.SearchRoot = 'LDAP://DC=cmc,DC=com'
$Result = $Searcher.FindOne()

IF( $Result -eq $null)
{
Write-Host "Group does not exist"
}
Else 
{              
Write-Host "Group exists"
}