术语 | netgroupenum |
释义 | NetGroupEnum 语法: C++ NET_API_STATUS NetGroupEnum( __in LPCWSTR servername, __in DWORD level, __out LPBYTE *bufptr, __in DWORD prefmaxlen, __out LPDWORD entriesread, __out LPDWORD totalentries, __inout PDWORD_PTR resume_handle ); NetGroupEnum功能 该NetGroupEnum函数检索信息安全中的每个数据库,这是安全帐户管理器(SAM)数据库或全局组,在域控制器的情况下,Active Directory中。 该NetQueryDisplayInformation功能提供了枚举全局组的有效机制。如果可能,建议您使用NetQueryDisplayInformation而不是NetGroupEnum功能。 参数 服务器名 [in] 指针常量字符串指定的DNS或NetBIOS的远程服务器上的功能是执行的名称。如果该参数为NULL,则使用本地计算机。 Level [in] 指定的数据信息的Level。此参数可以是下列值之一。 ValueMeaning 0Return全局组的名称。 The bufptr parameter points to an array of GROUP_INFO_0 structures. 1Return的全局组名称和评论。在bufptr参数指向一个GROUP_INFO_1结构的数组。 2Return详细资料,说明全局组。在bufptr参数指向一个GROUP_INFO_2结构的数组。请注意,在Windows XP和更高,建议您使用GROUP_INFO_3代替。 3Return详细资料,说明全局组。在bufptr参数指向一个GROUP_INFO_3结构的数组。 Windows 2000中:此级别不支持。 bufptr [out] 缓冲区指针获得国际组信息结构。这一数据格式取决于Level的参数值。 该系统分配此缓冲存储器。您必须调用NetApiBufferFree函数来释放内存。请注意,您必须释放缓冲区,即使函数ERROR_MORE_DATA失败。 prefmaxlen [in] 指定返回数据的首选的最大字节长度。如果您指定MAX_PREFERRED_LENGTH,该函数分配的内存量需要保存数据。如果指定这个参数在另一个值,它可以限制的字节数函数返回。如果缓冲区大小不足以容纳所有作品,该函数返回ERROR_MORE_DATA。有关更多信息,请参阅网络管理功能,缓冲器和网络管理功能缓冲区长度。 entriesread [out] 指针的值,它接收元素计数实际列举。 totalentries [out] 指针的值,它接收了本来可以列举参赛总人数从目前的恢复情况。今年参赛作品的数目只有一个提示。有关确定的参赛作品的确切数字信息,请参阅下面的备注部分。 resume_handle [ in , out ] 指针变量,它包含简历处理,用于继续全局组枚举。手柄应在第一次调用零,离开后续调用不变。如果该参数是NULL,没有恢复处理存储。 返回值 如果函数成功,返回值是NERR_Success。 如果函数失败,返回值可以是下面的错误代码之一。 返回codeDescription ERROR_ACCESS_DENIEDThe用户没有获得所需的信息。 NERR_InvalidComputerThe计算机名无效。 ERROR_MORE_DATAMore项可用。指定一个足够大的缓冲区接收的所有条目。 备注 如果您是Active Directory的程序,您可以调用某些Active Directory服务接口(ADSI)的方法来达到同样的功能,您可以通过调用实现网络管理小组的职能。有关更多信息,请参阅IADsGroup。 如果您调用域控制器上运行Active Directory的这一功能,允许访问或拒绝的访问控制列表的安全对象(ACL)的基础。默认的ACL允许所有经过身份验证的用户和“前成员,Windows 2000兼容访问”组查看信息。如果您调用一个成员服务器或工作站,所有的身份验证的用户可以查看此功能的信息。有关匿名访问的信息,并限制在这些平台上匿名访问,看到了网络管理功能的安全要求。欲了解更多有关的ACL,ACE的,和访问令牌信息,请访问控制模型。 该函数只返回信息,而来电者具有读取权限。调用者必须具有名单到域对象的内容访问,并列举整个SAM域上的SAM服务器访问对象在系统容器中。 为了确定确切的团体总数,您必须枚举整个树,它可以是一个昂贵的行动。枚举整个树,使用resume_handle参数继续枚举连续通话,并使用entriesread参数来积累的组总数。如果您的应用是与域控制器进行通讯,您应该考虑使用ADSI LDAP提供检索此类型的数据更有效。在ADSI LDAP提供程序实现了ADSI对象集,支持各种ADSI接口。有关更多信息,请参阅ADSI的服务提供商。 用户帐户名称被限制为20个字符和组名称被限制为256个字符。此外,帐户名称不能终止的期间,他们不能包含逗号或以下打印字符:“,/,\\,[,]:,|,”,“+,=,,,?, *.名称也不能包括在1-31范围内,这些非打印字符。 要求: 最低支持:client-Windows 2000专业版 最低支持server-Windows 2000服务器 HeaderLmaccess.h(包括Lm.h) LibraryNetapi32.lib DLLNetapi32.dll 参见 网络管理概述 网络管理功能 集团职能 GROUP_INFO_0 GROUP_INFO_1 GROUP_INFO_3 NetQueryDisplayInformation NetGroupGetInfo NetGroupGetUsers NetApiBufferFree 如果有任何问题和意见,请发送给微软(wsddocfb@microsoft.com) 生成日期:2009年8月13日 ==英文原文==NetGroupEnum Function The NetGroupEnum function retrieves information about each global group in the security database, which is the security accounts manager (SAM) database or, in the case of domain controllers, the Active Directory. The NetQueryDisplayInformation function provides an efficient mechanism for enumerating global groups. When possible, it is recommended that you use NetQueryDisplayInformation instead of the NetGroupEnum function. Syntax C++ NET_API_STATUS NetGroupEnum( __in LPCWSTR servername, __in DWORD level, __out LPBYTE *bufptr, __in DWORD prefmaxlen, __out LPDWORD entriesread, __out LPDWORD totalentries, __inout PDWORD_PTR resume_handle ); Parameters servername [in] Pointer to a constant string that specifies the DNS or NetBIOS name of the remote server on which the function is to execute. If this parameter is NULL, the local computer is used. level [in] Specifies the information level of the data. This parameter can be one of the following values. ValueMeaning 0Return the global group name. The bufptr parameter points to an array of GROUP_INFO_0 structures. 1Return the global group name and a comment. The bufptr parameter points to an array of GROUP_INFO_1 structures. 2Return detailed information about the global group. The bufptr parameter points to an array of GROUP_INFO_2 structures. Note that on Windows XP and later, it is recommended that you use GROUP_INFO_3 instead. 3Return detailed information about the global group. The bufptr parameter points to an array of GROUP_INFO_3 structures. Windows 2000: This level is not supported. bufptr [out] Pointer to the buffer to receive the global group information structure. The format of this data depends on the value of the level parameter. The system allocates the memory for this buffer. You must call the NetApiBufferFree function to deallocate the memory. Note that you must free the buffer even if the function fails with ERROR_MORE_DATA. prefmaxlen [in] Specifies the preferred maximum length of the returned data, in bytes. If you specify MAX_PREFERRED_LENGTH, the function allocates the amount of memory required to hold the data. If you specify another value in this parameter, it can restrict the number of bytes that the function returns. If the buffer size is insufficient to hold all entries, the function returns ERROR_MORE_DATA. For more information, see Network Management Function Buffers and Network Management Function Buffer Lengths . entriesread [out] Pointer to a value that receives the count of elements actually enumerated. totalentries [out] Pointer to a value that receives the total number of entries that could have been enumerated from the current resume position. The total number of entries is only a hint. For more information about determining the exact number of entries, see the following Remarks section. resume_handle [in, out] Pointer to a variable that contains a resume handle that is used to continue the global group enumeration. The handle should be zero on the first call and left unchanged for subsequent calls. If this parameter is NULL, no resume handle is stored. Return Value If the function succeeds, the return value is NERR_Success. If the function fails, the return value can be one of the following error codes. Return codeDescription ERROR_ACCESS_DENIEDThe user does not have access to the requested information. NERR_InvalidComputerThe computer name is invalid. ERROR_MORE_DATAMore entries are available. Specify a large enough buffer to receive all entries. Remarks If you are programming for Active Directory, you may be able to call certain Active Directory Service Interface (ADSI) methods to achieve the same functionality you can achieve by calling the network management group functions. For more information, see IADsGroup . If you call this function on a domain controller that is running Active Directory, access is allowed or denied based on the access control list (ACL) for the securable object . The default ACL permits all authenticated users and members of the " Pre-Windows 2000 compatible access " group to view the information. If you call this function on a member server or workstation, all authenticated users can view the information. For information about anonymous access and restricting anonymous access on these platforms, see Security Requirements for the Network Management Functions . For more information on ACLs, ACEs, and access tokens, see Access Control Model . The function only returns information to which the caller has Read access. The caller must have List Contents access to the Domain object, and Enumerate Entire SAM Domain access on the SAM Server object located in the System container. To determine the exact total number of groups, you must enumerate the entire tree, which can be a costly operation. To enumerate the entire tree, use the resume_handle parameter to continue the enumeration for consecutive calls, and use the entriesread parameter to accumulate the total number of groups. If your application is communicating with a domain controller, you should consider using the ADSI LDAP Provider to retrieve this type of data more efficiently. The ADSI LDAP Provider implements a set of ADSI objects that support various ADSI interfaces. For more information, see ADSI Service Providers . User account names are limited to 20 characters and group names are limited to 256 characters. In addition, account names cannot be terminated by a period and they cannot include commas or any of the following printable characters: ", /, \\, [, ], :, |, <, >, +, =, ;, ?, *. Names also cannot include characters in the range 1-31, which are nonprintable. Requirements Minimum supported clientWindows 2000 Professional Minimum supported serverWindows 2000 Server HeaderLmaccess.h (include Lm.h) LibraryNetapi32.lib DLLNetapi32.dll See Also Network Management Overview Network Management Functions Group Functions GROUP_INFO_0 GROUP_INFO_1 GROUP_INFO_3 NetQueryDisplayInformation NetGroupGetInfo NetGroupGetUsers NetApiBufferFree Send comments about this topic to Microsoft Build date: 8/13/2009 ==原始网址==http://msdn.microsoft.com/en-us/library/aa370428(VS.85).aspx\n |
随便看 |
|
windows api函数参考手册包含2258条windows api函数文档,详细介绍nodejs、java、rust调用windows api的方法技巧,是学习windows api编程的入门中文文档。