²©¿Íͳ¼ÆÐÅÏ¢

Óû§Ãû£ºyanxiaolu
ÎÄÕÂÊý£º17
ÆÀÂÛÊý£º8
·ÃÎÊÁ¿£º16916
ÎÞÓDZңº287
²©¿Í»ý·Ö£º497
²©¿ÍµÈ¼¶£º3
×¢²áÈÕÆÚ£º2007-06-19

ÓÃÓÚ¹ÜÀí Active Directory µÄ 11 ¸ö»ù±¾¹¤¾ß(¶þ)
2009-08-24 13:08:37
±êÇ©£ºÐÝÏÐ ad Ö°³¡
һЩµÚÈý·½²úÆ·
ÓÉÓÚ Active Directory »ùÓÚ LDAP ±ê×¼£¬Äú¿ÉÒÔʹÓÃÈκÎÖ§³Ö LDAP µÄ¹¤¾ß¶ÔÆä½øÐвéѯºÍÐ޸ġ£Ðí¶àµÚÈý·½¹©Ó¦ÉÌÒÑ·¢²¼ÁËÊշѵŤ¾ß£¬°ïÖúÄú¹ÜÀí Active Directory£¬µ«ÓÐʱÄú»á·¢ÏÖΪÉçÇøÃâ·ÑÌṩµÄ¼«¾ß¼ÛÖµµÄ¹¤¾ß¡£Ä¿Â¼·þÎñ MVP Joe Richards ´´½¨µÄ¼¯ºÏ¾ÍÊÇÕâÖÖÇé¿ö£¬¿ÉÒÔ´Ó joeware.net/freetools ÏÂÔØ¡£ÔÚÄÇÀïÄú½«»á·¢ÏÖ´óÁ¿¾ßÓв»Í¬¹¦ÄܵŤ¾ß¡£ÎÒ·´¸´Ê¹ÓõÄÓÐ adfind¡¢admod ºÍ oldcmp ÕâÈýÖÖ¹¤¾ß¡£

Adfind ºÍ Admod
Adfind ºÍ admod ÀàËÆÓÚ dsquery ºÍ dsmod£»adfind ÊÇ Active Directory µÄÃüÁîÐвéѯ¹¤¾ß£¬admod Äܹ»´´½¨¡¢É¾³ý»òÐÞ¸ÄÒ»¸ö»ò¶à¸ö Active Directory ¶ÔÏó¡£
Óë¾ßÓжà¸ö×Ӳ˵¥²¢ÇÒ¿ª¹ØÒÀ¾Ý¶ÔÏóÀàÐͶøÒìµÄ ds* ¹¤¾ß²»Í¬£¬adfind ºÍ admod ¾ßÓÐÒ»ÖµÄÓï·¨£¬ÓëÒª³¢ÊÔÖ´ÐеIJéѯ»òÐÞ¸ÄÀàÐÍÎ޹ء£adfind µÄ»ù±¾Ó﷨Ϊ£º
adfind ¨Cb <Search Base> -s <Search Scope> -f <Search Filter>
    attributesDesired
ËùÒÔ¶ÔÓòÖÐËùÓмÆËã»ú¶ÔÏóµÄ DN ºÍ˵Ã÷µÄ²éѯӦΪ£º
adfind ¨Cb dc=contoso,dc=com ¨Cs subtree ¨Cf (objectclass=computer) dn 
    description
¶ÔËùÓÐÓû§¶ÔÏóµÄ²éѯÈçÏÂËùʾ£º
adfind ¨Cb dc=contoso,dc=com ¨Cs subtree ¨Cf "(&(objectcategory=person)
    (objectclass=user))" dn description
×¢Ò⣬³ýÁË LDAP ²éѯµÄÄÚÈÝÍ⣬Ó﷨ûÓÐÈκθü¸Ä¡£
ʹÓà adfind ʱ£¬Äú½«·¢ÏÖÐí¶à¿ì½Ý²Ù×÷·û£¬¿ÉÒÔ¼õÉÙÐí¶à¼üÈëÄÚÈÝ¡£ÀýÈ磬-default ¿ª¹Ø¿ÉÒÔÈ¡´úÉÏһʾÀýÖÐµÄ -b dc=contoso,dc=com ²¢ËÑË÷Õû¸öÓò£»-gc ËÑË÷À¬»øÊÕ¼¯ (GC) ²¢·µ»Ø Active Directory ÁÖÖÐËùÓеÄÓû§¡£»¹¿ÉÒÔʹÓà -rb ¿ª¹ØÉèÖÃÏà¶ÔËÑË÷¿â£»Èç¹ûÒªÔÚ phl.east.us.contoso.com ÓòÖÐËÑË÷ Training OU£¬Äú¿ÉÒÔͨ¹ý½ö½öÖ¸¶¨ ¨Cdefault ¨Crb ou=Training£¬¶ø·Ç ¨Cb ou=Training, dc=phl,dc=east,dc=us,dc=contoso,dc=com£¬´Ó¶ø¼õÉÙÐí¶à¹¤×÷Á¿¡£
ÁíÍ⣬adfind »¹¿ÉÒÔÖ´ÐÐÔÚÃüÁîÐÐÖв»ÄÜÇáËɹÜÀíµÄÐí¶à¸ß¼¶ËÑË÷¹¦ÄÜ£¬Èçͼ 4 Ëùʾ¡£

¿ª¹ØËµÃ÷
-showdel²éѯ Deleted Objects ÈÝÆ÷£¬²éÕÒÂß¼­É¾³ý¶ÔÏó¡£
-bit²éѯ user AccountControl ÊôÐÔÖ®ÀàµÄλÔËËã·û¡£
-asqÖ´ÐÐÊôÐÔ·¶Î§²éѯ¡£´Ë¹¦ÄÜ£¨ÔÚ dsquery Öв»ÄÜʹÓã©¿ÉÒÔ¼ìË÷ÌØ¶¨¶ÔÏóµÄÊôÐÔ£¬È»ºó¶ÔÆäÖ´Ðвéѯ¡£
-dsq½« adfind ²éѯµÄ½á¹ûͨ¹ý¹ÜµÀ´«Ë͵½ dsmod »òÆäËû ds* ¹¤¾ßÖ®Ò»¡£
  
ʹÓà ¨Casq ¿ª¹Ø¡°ÏÔʾ HelpDesk ³ÉÔ±µÄ×é³ÉÔ±Éí·Ý¡±µÄʾÀýÈçÏÂËùʾ£º
adfind ¨Cdefault ¨Crb cn=HelpDesk,ou=IT ¨Casq member memberOf 
¹ËÃû˼Ò壬admod ÓÃÓÚÐÞ¸Ä Active Directory ÖеĶÔÏó¡£Óë adfind Ò»Ñù£¬²»ÐèÒª¼ÇסÓÐÌØÊâÓï·¨µÄÌØ¶¨×Ӳ˵¥£»admod ÔÚÈκÎʱºò¶¼Ê¹ÓÃÏàͬµÄÓï·¨£¬ÓëÒª´¦ÀíµÄ¶ÔÏóÀàÐÍÎ޹ء£»¹¿ÉÒÔʹÓà admod Ìí¼Ó¡¢Òƶ¯¡¢ÖØÃüÃû¡¢É¾³ýÉõÖÁ»Ö¸´¶ÔÏó£¬Ö»Ðèͨ¹ýÌí¼ÓÏàÓ¦µÄ¿ª¹Ø£¨Èç -add¡¢-rm¡¢-move¡¢-undel£©¼´¿ÉʵÏÖ¡£¾ÍÏñ dsquery ºÍ dsmod Ò»Ñù£¬ÄúÒ²¿ÉÒÔʹÓà | ×Ö·û½« adfind ²éѯµÄ½á¹ûͨ¹ý¹ÜµÀ´«Ë͵½ admod¡£
Çë×¢Ò⣬ʹÓà admod Ö´Ðлָ´²Ù×÷Ö»ÄÜÖ´ÐÐÂß¼­É¾³ý»Ö¸´²Ù×÷£¬Ôڴ˲Ù×÷Öд󲿷ֶÔÏóÊôÐÔÒѱ»É¾³ý¡£ÒªÍêÈ«»¹Ô­Ä³¸ö¶ÔÏó¼°ÆäËùÓÐÊôÐÔ£¬ÄúÈÔÐèÒªÖ´ÐиöÔÏóµÄÊÚȨ»¹Ô­¡£

Oldcmp
»¹ÓÐÒ»¸ö joeware ¹¤¾ß£¬ÎÒÈÏΪËüÊÇ×Ô¶¯¹¤¾ß°üÖбز»¿ÉÉÙµÄÒ»²¿·Ö£ºoldcmp£¬¸Ã¹¤¾ß»áɨÃè Active Directory Êý¾Ý¿â£¬²éÕÒÔÚÖ¸¶¨ÖÜÊýÄÚδʹÓõļÆËã»úÕÊ»§£¬¶øÇÒ¿ÉÒÔÖ´ÐÐÒÔϲÙ×÷£º
  • ´´½¨ÕÊ»§±¨±í¶ø²»¶ÔÆä½øÐÐÈκβÙ×÷
  • ½ûÓÃδʹÓõļÆËã»úÕÊ»§
  • ½«¼ÆËã»úÕÊ»§Òƶ¯µ½ÁíÒ»¸öÖ¸¶¨µÄ OU ÖÐ
  • Íêȫɾ³ý¼ÆËã»úÕÊ»§
Çë×¢Ò⣬ÓÉÓÚ oldcmp ¿ÉÄÜ»áÑÏÖØËð»µÄúµÄĿ¼£¬Òò´ËËüÓÐÐí¶àÄÚÖõݲȫ¹¦ÄÜ¡£Ëü²»»áɾ³ýÉÐδ½ûÓõÄÈκÎÕÊ»§£¨ÎÞÐèÊÖ¶¯Ö¸¶¨¡°No really, I mean it!¡±ÃüÁîÐпª¹Ø£©¡£ÎÞÐèÖ¸¶¨ÀàËÆµÄ¡°No really, I mean it!¡±¿ª¹Ø£¬Ã¿´ÎÐ޸ĶÔÏ󲻻ᳬ¹ý 10 ¸ö£¬¶øÇÒ¾ø¶Ô²»»á¶ÔÓò¿ØÖÆÆ÷µÄ¼ÆËã»úÕÊ»§Ö´ÐÐÈκβÙ×÷¡£
ÏÖÔÚ£¬¾¡¹Ü¹¤¾ßµÄÃû³ÆÒ×ÓÚÎóµ¼£¬µ«ÊÇ Joe ÒѸüÐÂÁË oldcmp£¬ÒÔ±ã¶ÔÔÚÌØ¶¨Ê±¼äÄÚδʹÓõÄÓû§ÕÊ»§Ò²ÄÜÖ´ÐÐÏàËÆµÄ¹¦ÄÜ¡£
¶ÔÓÚÒ»¸öСÐÍ Active Directory »·¾³»òÿ´ÎÖ»Ö´ÐÐÒ»Á½¸öÌí¼Ó»ò¸ü¸Ä²Ù×÷µÄ»·¾³£¬GUI ¹¤¾ß£¨Èç Active Directory Óû§ºÍ¼ÆËã»ú£©¿ÉÄÜ×ãÒÔÂú×ãÈÕ³£¹ÜÀíÐèÒª¡£µ«ÊÇ£¬Èç¹ûÄúÿÌì¶¼ÒªÌí¼ÓºÍÐ޸ĴóÁ¿¶ÔÏ󣬻òÕßÖ»ÊÇÐèÒª¸ü¼Ó¼ò»¯µØ¹ÜÀíÈÎÎñ½â¾ö·½°¸£¬Ôò¸ÄÓÃÃüÁîÐпÉÒÔ´ó´ó¼Ó¿ìÔÚ Active Directory Öд´½¨¡¢Ð޸ĺÍɾ³ý¶ÔÏóµÄ¹ý³Ì¡£ÄúÒѾ­Á˽⵽£¬ÓÐÐí¶àÁé»îÇÒ¹¦ÄÜÇ¿´óµÄ¹¤¾ß¿ÉÒÔÃâ·Ñ»ñµÃ£¬ËüÃÇ»òÕßÄÚÖÃÓÚ Windows ÖУ¬»òÕß¿É´Ó Active Directory ÉçÇø³ÉÔ±ÖÐÏÂÔØ¡£ÕâЩ¹¤¾ßÖеÄÈκÎÒ»¸ö¶¼Äܹ»´ó´óÌá¸ß Active Directory ¹ÜÀíÔ±µÄ¹¤×÷ЧÂÊ£¬Óë´Ëͬʱ£¬ËüÃÇÔÚÄúµÄÈÕ³£¹¤×÷ÖбäµÃ¸ü¼Ó±ØÒª¡£
·ÖÏíÖÁ
¸ü¶à
Ò»¼üÊղأ¬ËæÊ±²é¿´£¬·ÖÏíºÃÓÑ£¡
0ÈË
ÁËÕâÆªÎÄÕÂ
Àà±ð£ºWindows Server©ª¼¼ÊõȦ()©ªÔĶÁ()©ªÆÀÂÛ() ©ª ÍÆË͵½¼¼ÊõȦ©ª·µ»ØÊ×Ò³

ÎÄÕÂÆÀÂÛ

 
 

·¢±íÆÀÂÛ            

¡¾¼¼ÊõÃÅÕר¼Ò½âÎö£ºÈí¿¼ÖØµãÄѵ㼰ӦÊÔ¼¼ÇÉ
êÇ  ³Æ£º
µÇ¼  ¿ìËÙ×¢²á
ÑéÖ¤Â룺

Çëµã»÷ºóÊäÈëÑéÖ¤Â벩¿Í¹ý2¼¶£¬ÎÞÐèÌîдÑéÖ¤Âë

ÄÚ  ÈÝ£º