使用Python从安全组中删除AD用户

rya*_*sin 7 python pywin32 active-directory

我试图使用Python和pywin32从安全组中删除用户,但到目前为止还没有成功.但是,我可以将用户添加到安全组.

from win32com.client import GetObject

grp = GetObject("LDAP://CN=groupname,OU=groups,DC=blah,DC=local")

grp.Add("LDAP://CN=username,OU=users,DC=blah,DC=local") # successfully adds a user to the group

grp.Remove("LDAP://CN=username,OU=users,DC=blah,DC=local") # returns an error
Run Code Online (Sandbox Code Playgroud)

错误如下:

Traceback (most recent call last):
  File "<stdin>", line 1, in <module>
  File "<COMObject LDAP://CN=groupname,OU=groups,DC=blah,DC=local>", line 2, in Remove
pywintypes.com_error: (-2147352567, 'Exception occurred.', (0, None, None, None,
 0, -2147024891), None)
Run Code Online (Sandbox Code Playgroud)

我也尝试使用GetObject添加来获取用户并以这种方式删除它,但是我得到了同样的错误.

usr = GetObject("LDAP://CN=user,OU=users,DC=blah,DC=local")

grp.Remove(usr)
Run Code Online (Sandbox Code Playgroud)

任何帮助都会非常感激,因为我在这里遇到了死胡同.

编辑

我现在也尝试使用Tim Golden的active_directory模块来尝试删除组成员.

import active_directory as ad

grp = ad.find_group("groupname")
usr = ad.find_user("username")

grp.remove(usr.path())
Run Code Online (Sandbox Code Playgroud)

但是这也行不通,我遇到了以下错误.

Traceback (most recent call last):
  File "C:\Python33\lib\site-packages\active_directory.py", line 799, in __getat
tr__
    attr = getattr(self.com_object, name)
AttributeError: 'PyIADs' object has no attribute 'group'

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "C:\Python33\lib\site-packages\active_directory.py", line 802, in __getat
tr__
    attr = self.com_object.Get(name)
pywintypes.com_error: (-2147463155, 'OLE error 0x8000500d', (0, 'Active Director
y', 'The directory property cannot be found in the cache.\r\n', None, 0, -214746
3155), None)

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "<stdin>", line 1, in <module>
  File "C:\Python33\lib\site-packages\active_directory.py", line 1081, in remove

    self.group.Remove(dn)
  File "C:\Python33\lib\site-packages\active_directory.py", line 804, in __getat
tr__
    raise AttributeError
AttributeError
Run Code Online (Sandbox Code Playgroud)

编辑

Wherby建议我改用Python 2.7并给它一个去.我刚试过这个:

import active_directory as ad

user = ad.find_user("username")
group = ad.find_group("groupname")

group.remove(user.path())
Run Code Online (Sandbox Code Playgroud)

......但我仍然收到错误

Traceback (most recent call last):
  File "<stdin>", line 1, in <module>
  File "<COMObject LDAP://CN=groupname,OU=groups,DC=blah,DC=local>", line 2, in remove
pywintypes.com_error: (-2147352567, 'Exception occurred.', (0, None, None, None,
 0, -2147024891), None)
Run Code Online (Sandbox Code Playgroud)

确实可以正确找到用户和组,因为我可以使用print user.path()和打印他们的LDAP路径print group.path()

是否有任何其他人可以推荐的Python 3.3的其他活动目录库?

rya*_*sin 0

好吧,我走了之后发现我有点像个布偶。我登录的帐户没有从 AD 组中删除的权限。当我以网络管理员帐户登录时,它就像一个魅力。

最终代码:

from win32com.client import GetObject

group = GetObject("LDAP://CN=groupname,OU=Groups,DC=blah,DC=local")

group.Remove("LDAP://CN=username,OU=Users,DC=blah,DC=local")
Run Code Online (Sandbox Code Playgroud)