You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Intune部署壁纸脚本异常:本地正常但仅下载图片不更新壁纸

问题分析

Intune部署PowerShell脚本时默认以SYSTEM系统账户运行,这和本地测试用的当前用户上下文完全不同,导致两个核心问题:

  • 修改HKCU:\Control Panel\Desktop实际是修改SYSTEM账户的注册表项,而非登录用户的个人注册表,用户会话无法读取该设置。
  • SystemParametersInfo需要在用户交互式会话中执行,SYSTEM账户没有桌面会话,刷新操作无法生效。
解决方案

针对Intune环境,需调整脚本的执行上下文和注册表操作逻辑,以下是两种可行方案:

方案1:Intune用户脚本部署(推荐)

将脚本改为用户上下文执行(Intune中选择「用户脚本」而非「设备脚本」),脚本会在每个用户登录时以当前用户身份运行:

# 定义壁纸URL和用户可访问的目标路径
$WallpaperURL = "https://path/to/wallpaper"
$DestinationFolder = "$env:USERPROFILE\Pictures\Wallpaper"
$WallpaperPath = "$DestinationFolder\wallpaper.jpg"

# 确保目标文件夹存在
if (-not (Test-Path -Path $DestinationFolder)) {
    New-Item -Path $DestinationFolder -ItemType Directory -Force
}

# 下载壁纸(添加-UseBasicParsing提升兼容性)
try {
    Invoke-WebRequest -Uri $WallpaperURL -OutFile $WallpaperPath -TimeoutSec 30 -UseBasicParsing
} catch {
    exit 1
}

# 设置当前用户注册表项
try {
    Set-ItemProperty -Path "HKCU:\Control Panel\Desktop" -Name "Wallpaper" -Value $WallpaperPath
    Set-ItemProperty -Path "HKCU:\Control Panel\Desktop" -Name "WallpaperStyle" -Value 2  # 2=拉伸
    Set-ItemProperty -Path "HKCU:\Control Panel\Desktop" -Name "TileWallpaper" -Value 0   # 禁用平铺
} catch {
    exit 1
}

# 在用户会话中刷新桌面
try {
    Add-Type -TypeDefinition @'
using System;
using System.Runtime.InteropServices;
public class Wallpaper {
    [DllImport("user32.dll", CharSet = CharSet.Auto)]
    public static extern int SystemParametersInfo(int uAction, int uParam, string lpvParam, int fuWinIni);
}
'@
    [Wallpaper]::SystemParametersInfo(0x0014, 0, $WallpaperPath, 0x01 -bor 0x02)
} catch {
    exit 1
}

方案2:Active Setup实现全域用户生效

如果需要让所有现有和新用户都生效,可通过修改默认用户注册表+Active Setup触发用户登录时执行刷新:

# 定义全局可访问的壁纸路径(所有用户需有读取权限)
$WallpaperURL = "https://path/to/wallpaper"
$DestinationFolder = "C:\ProgramData\Wallpaper"
$WallpaperPath = "$DestinationFolder\wallpaper.jpg"

# 创建文件夹并设置用户读取权限
if (-not (Test-Path -Path $DestinationFolder)) {
    $folder = New-Item -Path $DestinationFolder -ItemType Directory -Force
    $acl = Get-Acl $folder.FullName
    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule("Users","ReadAndExecute","ContainerInherit,ObjectInherit","None","Allow")
    $acl.AddAccessRule($rule)
    Set-Acl $folder.FullName $acl
}

# 下载壁纸
try {
    Invoke-WebRequest -Uri $WallpaperURL -OutFile $WallpaperPath -TimeoutSec 30 -UseBasicParsing
} catch {
    exit 1
}

# 修改默认用户注册表(新用户登录时继承)
$defaultUserReg = "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Wallpapers"
Set-ItemProperty -Path $defaultUserReg -Name "BackgroundImagePath" -Value $WallpaperPath
Set-ItemProperty -Path $defaultUserReg -Name "BackgroundImageStyle" -Value 2

# 配置Active Setup,触发现有用户登录时刷新壁纸
$activeSetupPath = "HKLM:\SOFTWARE\Microsoft\Active Setup\Installed Components\WallpaperRefresh"
if (-not (Test-Path -Path $activeSetupPath)) {
    New-Item -Path $activeSetupPath -Force | Out-Null
}
Set-ItemProperty -Path $activeSetupPath -Name "StubPath" -Value "powershell.exe -Command ""Add-Type -TypeDefinition 'using System; using System.Runtime.InteropServices; public class WP { [DllImport(`"user32.dll`")] public static extern int SystemParametersInfo(int uAction, int uParam, string lpvParam, int fuWinIni); }'; [WP]::SystemParametersInfo(0x0014, 0, '$WallpaperPath', 0x01 -bor 0x02)"""
Set-ItemProperty -Path $activeSetupPath -Name "Version" -Value "1,0,0,0"
关键注意事项
  • 确保壁纸路径对目标用户有读取权限,避免权限不足导致无法加载。
  • 若使用HTTPS下载,需确保Intune设备能访问该URL,必要时配置代理或允许出站流量。
  • 可通过Get-WinEvent -LogName Microsoft-Windows-IntuneManagementExtension/Operational查看脚本执行日志,排查错误。

内容的提问来源于stack exchange,提问作者D.Ekanayaka

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 21:43:12