通过GPO以NT Authority\System身份运行字体安装脚本时遇Event 1202及脚本未执行问题求助
我正在为企业应用部署条形码字体,GPO服务器是Windows Server 2019 Standard(版本1809,OS构建17763.4252)。我通过计算机偏好设置->计划任务配置了一个立即运行的字体安装脚本,但遇到了一系列问题,希望能得到帮助。
字体安装脚本内容
$fonts = (New-Object -ComObject Shell.Application).Namespace(0x14) $Path = Test-Path \\DC\netlogon\font\ if($Path -eq $true) { Write-EventLog -Source Application -LogName Application -EventId 301 -EntryType Information -Message "The Network Path is True" $fontFolder = "\\DC\NETLOGON\Font\ " $fontItem = Get-Item -Path $fontFolder $fontList = Get-ChildItem -Path "$fontItem\*" -Include ('*.fon','*.otf','*.ttc','*.ttf') $RegPath =(Test-Path 'HKCU:\Software\Microsoft\Windows NT\CurrentVersion\Fonts') $objFont = New-Object System.Drawing.Text.PrivateFontCollection } foreach ($font in $fontList) { $objFont.AddFontFile($font.FullName) $objTitle = $objFont.Families[-1].Name $fontName = $font.Name $objExtension = switch ($font.Extension) { .TTF {"(True Type Font)"} .OTF {"(Open Type Font)"} Default { Write-EventLog -Source Application -LogName Application -EventId 305 -EntryType Information -Message "Font Extension not Found" } } $FontTitle = $objTitle + " " + $objExtension if (-not(Test-Path -Path "C:\Windows\fonts\$fontName" )) { Write-EventLog -Source Application -LogName Application -EventId 302 -EntryType Information -Message "Font not Found, Installing font." echo $fontName reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts" /v $FontTitle /t REG_SZ /d DWBAR39.TTF /f cp $font C:\Windows\Fonts if (Test-Path -Path "C:\windows\fonts\$fontName") { Write-EventLog -Source Application -LogName Application -EventId 306 -EntryType Information -Message "Font Installed." } } elseif (Test-Path -Path "C:\Windows\fonts\$fontName"){ Write-EventLog -Source Application -LogName Application -EventId 303 -EntryType Information -Message "Font Already Installed in C:\windows\fonts\" } }
GPO计划任务配置详情
- 任务名称:C - Font Installer
- 作者:'Me'
- 描述:Installs fonts.
- 运行模式:仅当用户登录时(S4U)
- 用户ID:
NT AUTHORITY\System - 以最高权限运行:HighestAvailable
- 隐藏:是
- 配置版本:1.2
- 已启用:是
- 程序/脚本:
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe - 参数:
-ExecutionPolicy Bypass -Command '& \\DC\netlogon\add-Font.ps1' - 起始目录:
C:\Windows\System32\WindowsPowerShell - 其他规则:
- 计算机停止空闲时停止任务:是
- 空闲状态恢复时重新启动:否
- 仅在使用交流电时启动任务:是
- 切换到电池电源时停止任务:否
- 允许按需运行任务:是
- 计划启动错过后尽快运行:是
- 运行超过3天则强制停止:是
- 不再计划运行时立即删除任务:是
- 任务已在运行时:停止现有实例
遇到的问题与已尝试操作
- 本地运行正常,GPO执行出错:脚本在本地手动运行完全正常,但刷新组策略时会触发Event 1202, SceCLI,错误代码0x5(拒绝访问)。
- 防火墙禁用后仍无效果:我禁用了域范围的Windows防火墙,SceCLI错误不再出现,但脚本似乎根本没执行——我在脚本中添加的所有事件日志都没有任何记录。
- SYSTEM身份测试异常:用
PSEXEC64.exe -sid powershell以SYSTEM身份运行dir $font | %{$fonts.CopyHere($_.FullName)}时没有任何输出,推测可能是0x14 Shell命名空间被重定向到用户配置文件导致的问题,但即使调整了脚本,情况还是没有改善。
现在我最困惑的是:明明配置了以SYSTEM身份运行任务,为什么脚本完全没有执行的迹象?有没有办法解决这个问题?
备注:内容来源于stack exchange,提问作者Liam Chaney
相关产品推荐
相关产品推荐

