lenf 发表于 2018-9-1 13:09:50

Powershell管理系列(三十九)PowerShell查询和解锁AD账号

Import-Module activedirectory  
$yuntcloud_Lockeduser = Search-ADAccount -LockedOut -SearchBase "dc=yuntcloud,dc=com" -server dc01 | select name, samaccountname
  
$aaa_Lockeduser = Search-ADAccount -LockedOut -SearchBase "dc=aaa,dc=yuntcloud,dc=com" -server aaaDC1 | select name, samaccountname
  
$bbb_Lockeduser = Search-ADAccount -LockedOut -SearchBase "dc=bbb,dc=yuntcloud,dc=com" -server bbbdc1 | select name, samaccountname
  
$ccc_Lockeduser = Search-ADAccount -LockedOut -SearchBase "dc=ccc,dc=yuntcloud,dc=com" -server cccDC1 | select name, samaccountname
  
#send email
  
$UserName = "test01@yuntcloud.com" #定义管理员账户名称
  
$Password = ConvertTo-SecureString "Djds123" -AsPlainText –Force
  
$cred = New-Object System.Management.Automation.PSCredential($UserName, $Password)
  
$nFrom = "test01@yuntcloud.com"
  
$nTo = "zhouping@yuntcloud.com"
  
$lockeduser = @()
  
#Unlock yuntcloud Locked user
  
if (::IsNullOrEmpty($($yuntcloud_Lockeduser|%{$_.name})))
  
{
  
Write-Host "yuntcloud no locked user"
  
Start-Sleep 5
  
Send-MailMessage -From $nFrom -To $nTo -Subject "yuntcloud no locked user" -Body "yuntcloud no locked user" -Credential $cred -SmtpServer "mail.yuntcloud.com" -Encoding (::UTF8)
  
}
  
else
  
{
  
Write-Host "yuntcloud Locked user"
  
foreach ($i in $yuntcloud_Lockeduser)
  
{
  
Write-Host $i.name
  
$lockeduser += $i
  
}
  
Start-Sleep 5
  
Search-ADAccount -LockedOut -SearchBase "dc=yuntcloud,dc=com" -server dc01 | Unlock-ADAccount
  
Write-Host "yuntcloud all locked account were unlocked"
  
$lockeduser | Export-Csv -Path c:\yuntcloud_lockeduser.csv -NoTypeInformation -Encoding utf8
  
Send-MailMessage -From $nfrom -To $nto -Subject "yuntcloud locked user" -Body "yuntcloud locked user" -Attachments "c:\yuntcloud_lockeduser.csv" -Credential $cred -SmtpServer mail.yuntcloud.com -Encoding (::UTF8)
  
Start-Sleep 3
  
}
  
#Unlock aaa.yuntcloud.com Locked user
  
$lockeduser = @()
  
if (::IsNullOrEmpty($($aaa_Lockeduser|%{$_.name})))
  
{
  
Write-Host "aaa no locked user"
  
Start-Sleep 5
  
Send-MailMessage -From $nfrom -To $nto -Subject "aaa no locked user" -Body "aaa no locked user" -Credential $cred -SmtpServer mail.yuntcloud.com -Encoding (::UTF8)
  
}
  
else
  
{
  
Write-Host "aaa Locked user"
  
foreach ($i in $aaa_Lockeduser)
  
{
  
Write-Host $i.name
  
$lockeduser += $i
  
}
  
Start-Sleep 5
  
Search-ADAccount -LockedOut -SearchBase "dc=aaa,dc=yuntcloud,dc=com" -server aaaDC1 | Unlock-ADAccount
  
Write-Host "aaa all locked account were unlocked"
  
$lockeduser | Export-Csv -Path c:\aaa_lockeduser.csv -NoTypeInformation -Encoding utf8
  
Send-MailMessage -From $nfrom -To $nto -Subject "aaa locked user" -Body "aaa locked user" -Attachments "c:\aaa_lockeduser.csv" -Credential $cred -SmtpServer mail.yuntcloud.com -Encoding (::UTF8)
  
Start-Sleep 3
  
}
  
#Unlock bbb.yuntcloud.com Locked user
  
$lockeduser = @()
  
if (::IsNullOrEmpty($($bbb_Lockeduser|%{$_.name})))
  
{
  
Write-Host "bbb no locked user"
  
Start-Sleep 5
  
Send-MailMessage -From $nfrom -To $nto -Subject "bbb no locked user" -Body "bbb no locked user" -Credential $cred -SmtpServer mail.yuntcloud.com -Encoding (::UTF8)
  
}
  
else
  
{
  
Write-Host "bbb Locked user"
  
foreach ($i in $bbb_Lockeduser)
  
{
  
Write-Host $i.name
  
$lockeduser += $i
  
}
  
Start-Sleep 5
  
Search-ADAccount -LockedOut -SearchBase "dc=bbb,dc=yuntcloud,dc=com" -server bbbdc1 | Unlock-ADAccount
  
Write-Host "bbb all locked account were unlocked"
  
$lockeduser | Export-Csv -Path c:\bbb_lockeduser.csv -NoTypeInformation -Encoding utf8
  
Send-MailMessage -From $nfrom -To $nto -Subject "bbb locked user" -Body "bbb locked user" -Attachments "c:\bbb_lockeduser.csv" -Credential $cred -SmtpServer mail.yuntcloud.com -Encoding (::UTF8)
  
Start-Sleep 3
  
}
  
#Unlock ccc.yuntcloud.com Locked user
  
$lockeduser = @()
  
if (::IsNullOrEmpty($($ccc_Lockeduser|%{$_.name})))
  
{
  
Write-Host "ccc no locked user"
  
Start-Sleep 5
  
Send-MailMessage -From $nfrom -To $nto -Subject "ccc no locked user" -Body "ccc no locked user" -Credential $cred -SmtpServer mail.yuntcloud.com -Encoding (::UTF8)
  
}
  
else
  
{
  
Write-Host "ccc Locked user"
  
foreach ($i in $ccc_Lockeduser)
  
{
  
Write-Host $i.name
  
$lockeduser += $i
  
}
  
Start-Sleep 5
  
Search-ADAccount -LockedOut -SearchBase "dc=ccc,dc=yuntcloud,dc=com" -server cccDC1 | Unlock-ADAccount
  
Write-Host "ccc all locked account were unlocked"
  
$lockeduser | Export-Csv -Path c:\ccc_lockeduser.csv -NoTypeInformation -Encoding utf8
  
Send-MailMessage -From $nfrom -To $nto -Subject "ccc locked user" -Body "ccc locked user" -Attachments "c:\ccc_lockeduser.csv" -Credential $cred -SmtpServer mail.yuntcloud.com -Encoding (::UTF8)
  
Start-Sleep 3
  
}


页: [1]
查看完整版本: Powershell管理系列(三十九)PowerShell查询和解锁AD账号