You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

拥有管理员权限仍遇0x80070005权限拒绝,PowerShell更新脚本故障

解决PSWindowsUpdate远程执行更新时的0x80070005权限拒绝错误

核心问题分析

出现HRESULT: 0x80070005 (E_ACCESSDENIED)通常是因为远程会话权限未正确传递、远程主机UAC限制,或是WinRM配置未开放管理员级远程操作权限——即便本地拥有管理员权限,也可能因这些配置问题触发权限拒绝。

解决方案

1. 确保远程会话使用管理员权限

  • 本地必须以管理员身份启动PowerShell,否则远程会话会继承普通用户权限。
  • 创建会话时显式传递目标主机的管理员凭据,避免权限丢失:
    $adminCred = Get-Credential # 输入目标主机的管理员账号密码
    $session = New-PSSession -ComputerName $computer -Credential $adminCred
    

2. 解除远程主机的UAC权限过滤

默认Windows会限制本地管理员的远程权限,需修改注册表解除限制:

Invoke-Command -ComputerName $computer -Credential $adminCred -ScriptBlock {
    Set-ItemProperty -Path HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -Name LocalAccountTokenFilterPolicy -Value 1 -Type DWord
}

修改后无需重启即可生效。

3. 检查并配置远程主机WinRM

确保远程主机已启用PowerShell远程管理:

Invoke-Command -ComputerName $computer -Credential $adminCred -ScriptBlock {
    Enable-PSRemoting -Force
    Set-NetFirewallRule -Name WINRM-HTTP-In-TCP -RemoteAddress Any
}

4. 优化PSWindowsUpdate执行逻辑

  • 避免远程动态安装模块:提前在远程主机用管理员PowerShell安装模块,减少权限风险:
    Install-Module -Name PSWindowsUpdate -Force -SkipPublisherCheck -Scope AllUsers
    
  • 修改更新命令,取消交互并自动接受更新:
    Install-WindowsUpdate -AcceptAll -Install -AutoReboot -Confirm:$false
    

5. 直接使用模块的远程参数(替代PSSession)

PSWindowsUpdate部分命令支持直接指定-ComputerName,无需手动创建会话:

Get-WindowsUpdate -ComputerName $computer -AcceptAll -Install -AutoReboot

注意:此方式依赖WMI服务,需确保远程主机WMI服务运行且端口(135、445)开放。

修改后的完整脚本示例

$Window.FindName("WUforce").add_click({
    $info = $Window.FindName('info')
    $computer = $Window.FindName('PCWU').Text
    $info.Text = "Forcing updates on $computer..."
    
    try {
        # 获取远程管理员凭据
        $adminCred = Get-Credential -Message "Enter admin credentials for $computer"
        $session = New-PSSession -ComputerName $computer -Credential $adminCred
        
        Invoke-Command -Session $session -ScriptBlock {
            # 若已提前安装模块可注释此行
            Install-Module -Name PSWindowsUpdate -Force -SkipPublisherCheck -Scope AllUsers -ErrorAction Stop
            Import-Module PSWindowsUpdate -ErrorAction Stop
            
            # 自动执行更新并重启
            Install-WindowsUpdate -AcceptAll -Install -AutoReboot -Confirm:$false -ErrorAction Stop
        }
        
        $info.Text = "Windows updates have been installed and the computer may have restarted."
    } catch {
        $info.Text = "Error: $_"
    } finally {
        if ($session) { Remove-PSSession -Session $session }
    }
})

排查验证步骤

  • 测试远程会话权限:
    Invoke-Command -ComputerName $computer -Credential $adminCred -ScriptBlock { whoami /priv }
    
    检查输出是否包含SeSecurityPrivilege、SeTakeOwnershipPrivilege等管理员权限。
  • 测试Windows Update服务访问:
    Invoke-Command -ComputerName $computer -Credential $adminCred -ScriptBlock { Get-Service wuauserv }
    
    确保服务状态为Running。

内容的提问来源于stack exchange,提问作者promo 69

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 19:56:16