You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell中使用ActiveDirectoryAccessRule配置AD委托权限遇错求助

解决ActiveDirectoryAccessRule构造函数歧义错误问题

问题场景

尝试为所有后代对象委派“创建所有子对象”和“删除所有子对象”权限,GUI配置后对应的ACL信息如下:

ActiveDirectoryRights : CreateChild, DeleteChild
InheritanceType : All
ObjectType : 00000000-0000-0000-0000-000000000000
InheritedObjectType : 00000000-0000-0000-0000-000000000000
ObjectFlags : None
AccessControlType : Allow
IdentityReference : DOMAINGROUP
IsInherited : False
InheritanceFlags : ContainerInherit
PropagationFlags : None

尝试用System.DirectoryServices.ActiveDirectoryAccessRule复制该ACL时,多次调用构造函数均触发如下错误:

New-Object : Multiple ambiguous overloads found for "ActiveDirectoryAccessRule" and the argument count: "5".
    At line:1 char:9
    + $ace2 = New-Object System.DirectoryServices.ActiveDirectoryAccessRule ...
    +         ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
        + CategoryInfo          : InvalidOperation: (:) [New-Object], MethodException
        + FullyQualifiedErrorId : ConstructorInvokedThrowException,Microsoft.PowerShell.Commands.NewObjectCommand

解决方案

报错源于PowerShell无法自动匹配正确的ActiveDirectoryAccessRule构造函数重载——字符串参数可被解析为多种枚举类型,导致歧义。需明确指定参数类型或严格匹配构造函数参数顺序。

根据你的ACL配置,正确的代码写法如下:

方式一:使用明确枚举类型(推荐)

# 定义所需枚举与值
$adRights = [System.DirectoryServices.ActiveDirectoryRights]::CreateChild -bor [System.DirectoryServices.ActiveDirectoryRights]::DeleteChild
$accessControlType = [System.Security.AccessControl.AccessControlType]::Allow
$inheritanceType = [System.DirectoryServices.ActiveDirectorySecurityInheritance]::All
$emptyGuid = [System.Guid]::Empty

# 创建AccessRule对象
$ace2 = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
    $GroupSID,
    $adRights,
    $accessControlType,
    $emptyGuid,
    $inheritanceType,
    $emptyGuid
)

方式二:严格匹配构造函数参数顺序(字符串参数)

$ace2 = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
    $GroupSID,
    "CreateChild, DeleteChild",
    "Allow",
    [System.Guid]::Empty,
    "All",
    [System.Guid]::Empty
)

关键说明

  • 使用枚举类型替代纯字符串,可消除构造函数匹配歧义
  • 目标ACL中InheritanceType为All,对应枚举ActiveDirectorySecurityInheritance.All
  • ObjectType和InheritedObjectType均为空GUID,用[System.Guid]::Empty直接表示

内容的提问来源于stack exchange,提问作者Simon Royer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 21:13:17