执行Get-BpaModel遇执行策略覆盖错误,求解决方案
问题现象
运行Get-BpaModel命令时触发执行策略覆盖错误,具体报错如下:
Get-BpaModel : There has been an error while trying to set the process wide execution policy. (Inner Exception:
Windows PowerShell updated your execution policy successfully, but the setting is overridden by a policy defined at a
more specific scope. Due to the override, your shell will retain its current effective execution policy of
Unrestricted. Type "Get-ExecutionPolicy -List" to view your execution policy settings. For more information please see
"Get-Help Set-ExecutionPolicy".)
At line:1 char:1
- Get-BpaModel
+ CategoryInfo : NotSpecified: (:) [Get-BpaModel], CommandLetException + FullyQualifiedErrorId : SetExecutionPolicyError,Microsoft.BestPractices.Cmdlets.GetModelCommand
当前执行策略配置
执行Get-ExecutionPolicy系列命令结果:
PS C:\Windows\system32> Get-ExecutionPolicy Unrestricted PS C:\Windows\system32> Get-ExecutionPolicy -list Scope ExecutionPolicy ----- --------------- MachinePolicy Unrestricted UserPolicy Unrestricted Process RemoteSigned CurrentUser Bypass LocalMachine Unrestricted
已尝试操作
先执行Set-ExecutionPolicy Unrestricted再调用Get-BpaModel,仍触发相同错误:
PS C:\Windows\system32> Set-ExecutionPolicy Unrestricted | Get-BpaModel Execution Policy Change The execution policy helps protect you from scripts that you do not trust. Changing the execution policy might expose you to the security risks described in the about_Execution_Policies help topic at http://go.microsoft.com/fwlink/?LinkID=135170. Do you want to change the execution policy? [Y] Yes [A] Yes to All [N] No [L] No to All [S] Suspend [?] Help (default is "N"): y Get-BpaModel : There has been an error while trying to set the process wide execution policy. (Inner Exception: Windows PowerShell updated your execution policy successfully, but the setting is overridden by a policy defined at a more specific scope. Due to the override, your shell will retain its current effective execution policy of Unrestricted. Type "Get-ExecutionPolicy -List" to view your execution policy settings. For more information please see "Get-Help Set-ExecutionPolicy".) At line:1 char:36 + Set-ExecutionPolicy Unrestricted | Get-BpaModel + ~~~~~~~~~~~~ + CategoryInfo : NotSpecified: (:) [Get-BpaModel], CommandLetException + FullyQualifiedErrorId : SetExecutionPolicyError,Microsoft.BestPractices.Cmdlets.GetModelCommand
GPO配置情况
From the GPO: Policy Setting Winning GPO Turn on Script Execution Enabled Default Domain Policy Execution Policy Allow all scripts
解决办法
方法1:启动PowerShell时指定执行策略
打开命令提示符,运行以下命令启动PowerShell会话,直接指定Process级执行策略为Unrestricted:
powershell.exe -ExecutionPolicy Unrestricted
在新会话中执行Get-BpaModel,此时Process级策略与GPO的MachinePolicy一致,可避免内部设置时的覆盖冲突。
方法2:统一低优先级Scope的执行策略
将CurrentUser和LocalMachine级的执行策略设置为Unrestricted,确保与GPO策略一致:
Set-ExecutionPolicy Unrestricted -Scope CurrentUser -Force Set-ExecutionPolicy Unrestricted -Scope LocalMachine -Force
执行后重启PowerShell会话,再运行Get-BpaModel测试。
方法3:刷新GPO并验证配置
强制刷新组策略,确保GPO设置生效:
gpupdate /force
重启PowerShell会话后重新执行Get-BpaModel。
内容的提问来源于stack exchange,提问作者Boolog

