<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[gOxiA=苏繁=SuFan Blog]]></title> 
<link>https://goxia.maytide.net/index.php</link> 
<description><![CDATA[gOxiA,苏繁,sufan,Microsoft MVP]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[gOxiA=苏繁=SuFan Blog]]></copyright>
<item>
<link>https://goxia.maytide.net/read.php/1637.htm</link>
<title><![CDATA[[AD] HOWTO：删除 AD 内账号重复的 CN 名称]]></title> 
<author>gOxiA &lt;sufan_cn@msn.com&gt;</author>
<category><![CDATA[Windows Server]]></category>
<pubDate>Thu, 15 Nov 2012 12:36:19 +0000</pubDate> 
<guid>https://goxia.maytide.net/read.php/1637.htm</guid> 
<description>
<![CDATA[ 
	<p><a href="http://goxia.maytide.net/ftpupfiles/AD-HOWTO-AD--CN_116C8/image.png"><img title="image" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/AD-HOWTO-AD--CN_116C8/image_thumb.png" width="630" height="185"></a></p> <p><font color="#fd3f0d" size="4"><strong>HOWTO：删除 AD 内账号重复的 CN 名称</strong></font></p> <p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;近期 <a href="http://goxia.maytide.net/" target="_blank">gOxiA</a> 在公司 SBS 系统上的 Microsoft Baseline Configuration Analyzer 2.0 检测报告中发现了一条警告“One or more user accounts have duplicate CN names”大概的意思是说在我当前的 AD（活动目录）里发现一个或多个账号存在相同的 CN 名称。如下图所示：</p> <p><a href="http://goxia.maytide.net/ftpupfiles/AD-HOWTO-AD--CN_116C8/image_3.png"><img title="image" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/AD-HOWTO-AD--CN_116C8/image_thumb_3.png" width="634" height="343"></a></p> <p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;这要排查起来可老费时间和经理，还好利用 PowerShell 我们能够轻松的对 AD 进行筛选查询，为此登录 DC 服务器，到“管理工具”下找到“用于 Windows PowerShell 的 Active Directory 模块”并运行它，然后键入如下命令行：</p> <p><div class="code">(get-ADObject -searchscope subtree -filter &#039;objectCategory -eq &quot;user&quot;&#039; -Properties cn) &#124; foreach &#123;$_.cn.trim(&quot; &quot;)&#125;</div></p> <p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;查询结果中我们能很轻松的找到重复的账号，如下图：</p> <p><a href="http://goxia.maytide.net/ftpupfiles/AD-HOWTO-AD--CN_116C8/image_4.png"><img title="image" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; display: inline; padding-right: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/AD-HOWTO-AD--CN_116C8/image_thumb_4.png" width="521" height="474"></a></p> <p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;然后打开 ADUC，在“查看”菜单下启用“高级功能”后，再查找这个账号，这样除了能搜索到重复的账号以外，还能通过账号属性下“对象”选项卡确定该账号存储的位置。</p> <p><a href="http://goxia.maytide.net/ftpupfiles/AD-HOWTO-AD--CN_116C8/image_5.png"><img title="image" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; display: inline; padding-right: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/AD-HOWTO-AD--CN_116C8/image_thumb_5.png" width="578" height="474"></a></p> <p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;确认这些账号的存储位置之后，便可以对其隶属性进行分析，以确定该删除哪个账号。</p><br/>Tags - <a href="https://goxia.maytide.net/go.php/tags/microsoft/" rel="tag">microsoft</a> , <a href="https://goxia.maytide.net/go.php/tags/windows/" rel="tag">windows</a> , <a href="https://goxia.maytide.net/go.php/tags/server/" rel="tag">server</a> , <a href="https://goxia.maytide.net/go.php/tags/active/" rel="tag">active</a> , <a href="https://goxia.maytide.net/go.php/tags/directory/" rel="tag">directory</a> , <a href="https://goxia.maytide.net/go.php/tags/ad/" rel="tag">ad</a> , <a href="https://goxia.maytide.net/go.php/tags/cn/" rel="tag">cn</a> , <a href="https://goxia.maytide.net/go.php/tags/powershell/" rel="tag">powershell</a>
]]>
</description>
</item>
</channel>
</rss>