You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

带SSL的远程PowerShell连接报错:用户授权失败(错误5)

问题与解决方案

问题场景

  • 客户端:已加入域的Windows Server 2012 R2服务器
  • 目标端:未加入域、已应用CIS Level 1基准的Windows Server 2019服务器
  • 已完成配置:按PowerShell远程HTTPS教程配置,双方证书指纹确认无误
  • 执行脚本:
$Username = 'remoteServerName\remoteLocalAdminUser'
$Password = 'remoteUserPassword'
$pass = ConvertTo-SecureString -AsPlainText $Password -Force
$Cred = New-Object System.Management.Automation.PSCredential -ArgumentList $Username,$pass
Invoke-Command -ComputerName "remoteServerName" -useSSL -scriptblock {Get-Service} -Credential $Cred
  • 客户端报错:

[remoteServerName] Connecting to remote server remoteServerName failed with the following error message : Access is denied. For more information, see the about_Remote_Troubleshooting Help topic.

  • CategoryInfo : OpenError: (remoteServerName:String) [], PSRemotingTransportException
  • FullyQualifiedErrorId : AccessDenied,PSSessionStateBroken
  • 目标端WinRM操作日志(%SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-WinRM%4Operational.evtx)报错:The authorization of the user failed with error 5

排查与解决方案

1. 检查目标端本地管理员的WinRM权限

CIS Level 1基准可能限制了WinRM允许的用户组,在目标端执行以下命令确认权限配置:

Get-PSSessionConfiguration | Select-Object Name, Permission

若本地管理员组未在允许列表,通过以下命令添加权限:

Set-PSSessionConfiguration -Name Microsoft.PowerShell -ShowSecurityDescriptorUI

在弹出的安全设置窗口中,添加目标本地管理员用户/组,赋予Execute (Invoke)权限。

2. 禁用目标端UAC远程权限过滤

非域环境下,UAC默认会过滤本地管理员的远程权限,需修改注册表:
在目标端执行:

Set-ItemProperty -Path HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -Name LocalAccountTokenFilterPolicy -Value 1 -Type DWord

修改后重启WinRM服务:

Restart-Service WinRM

3. 启用目标端WinRM的NTLM身份验证

CIS基准可能禁用了非域环境常用的NTLM验证,检查当前配置:

Get-WSManInstance -ResourceURI winrm/config/service/auth -Enumerate

若NTLM显示为false,执行命令启用:

Set-Item -Path WSMan:\localhost\Service\Auth\NTLM -Value $true

4. 确认客户端信任目标端证书

将目标端WinRM证书导出为.cer文件,导入到客户端的本地计算机\受信任的根证书颁发机构存储中,然后测试HTTPS连接:

Test-WSMan -ComputerName remoteServerName -UseSSL

5. 检查目标端WinRM HTTPS防火墙规则

CIS基准可能严格限制端口,确认WinRM HTTPS默认端口(5986)已开放:

Get-NetFirewallRule -Name *WinRM-HTTPS*

若规则未启用,执行命令启用:

Enable-NetFirewallRule -Name WINRM-HTTPS-In-TCP

内容的提问来源于stack exchange,提问作者dazedandconfused

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 02:16:19