You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell添加域管理员文件夹权限:优化继承与避免不必要所有权变更

批量为域文件夹添加Domain Admins继承权限的PowerShell脚本优化

场景与目标

环境包含约150TB数据、数千个文件夹,需通过PowerShell自动化脚本,使用icacls和takeown为指定文件夹下所有对象/容器添加Domain Admins(或指定域组)的完全控制权限,要求:

  • 仅在顶层文件夹添加权限并向下自动继承,无重复权限条目
  • 尽量保留原有所有权,仅在必要时获取
  • 无需多次执行脚本

原有脚本及问题

原有脚本

$Permission = "(OI)(CI)F"
$Username = "Domain Admins"
$GrantString = $Username + ":" + $Permission

foreach ($Folder in $FoldersToFix) {
    try {
        icacls ""$Folder"" /C /Q /grant ""$GrantString"" /T
        Write-ToMyLog "Success: $Folder"
    }
    catch {
        Write-ToMyLog "Warning: failed to grant permission on folder $Folder (error was: $((_.Exception -split ":")[-1].Trim())). Trying to take ownership first..."
        try {
            takeown /F ""$Folder""
        }
        catch {
            Write-ToMyLog "Failed to take ownership for folder $Folder, error message was: $_"
            continue
        }
        try {
            icacls ""$Folder"" /C /Q /grant ""$GrantString"" /T
        }
        catch {
            Write-ToMyLog "Failed to update permissions for folder $Folder, error message was: $_"
            continue
        }
    }
}

当前问题

  • icacls的/T递归参数仅在已有权限的子文件夹生效,无权限时会报Access Denied,/reset参数无法解决该问题
  • takeown获取所有权会修改原有所有者,且部分嵌套文件夹无法被完全递归处理
  • icacls的/T会给每个对象添加显式权限,导致子文件夹出现继承+显式的重复权限条目,冗余且低效

优化方案与改进脚本

核心思路

  1. 仅在顶层文件夹添加带继承属性的权限:利用(OI)(CI)标记让权限自动向下继承,避免递归添加显式权限
  2. 按需获取所有权:仅在操作被拒绝时,递归获取当前文件夹及子对象的所有权,最小化对原有所有者的修改
  3. 修复权限继承中断:对中断继承的子对象重新启用继承,确保顶层权限能向下传递,同时清理冗余显式权限

改进后的脚本

# 配置参数
$TargetGroups = @("Domain Admins")  # 可添加多个目标域组
$PermissionMask = "(OI)(CI)F"
$LogPath = ".\PermissionFixLog.txt"

# 日志写入函数(替换为你现有的Write-ToMyLog逻辑)
function Write-ToMyLog {
    param([string]$Message)
    $timestamp = Get-Date -Format "yyyy-MM-dd HH:mm:ss"
    "$timestamp - $Message" | Out-File -FilePath $LogPath -Append -Encoding utf8
}

foreach ($Folder in $FoldersToFix) {
    Write-ToMyLog "Processing folder: $Folder"
    
    # 尝试直接为顶层文件夹添加继承权限(不递归)
    $grantSuccess = $false
    try {
        # /grant:r 替换现有同组权限,避免重复;不加/T,仅修改顶层
        icacls "$Folder" /C /Q /grant:r "$($TargetGroups[0]):$PermissionMask"
        $grantSuccess = $true
        Write-ToMyLog "Successfully added inherited permission to top-level folder: $Folder"
    }
    catch {
        $errorMsg = $_.Exception.Message.Split(":")[-1].Trim()
        Write-ToMyLog "Failed to grant permission on top-level folder: $Folder (Error: $errorMsg). Attempting to take ownership..."
    }

    # 添加权限失败时,递归获取当前文件夹树的所有权
    if (-not $grantSuccess) {
        try {
            # /R 递归处理子对象;/A 将所有权赋予域管理员组;/D Y 自动确认所有提示
            takeown /F "$Folder" /R /A /D Y
            Write-ToMyLog "Successfully took ownership recursively for: $Folder"
        }
        catch {
            Write-ToMyLog "Failed to take ownership for folder tree: $Folder (Error: $_.Exception.Message)"
            continue
        }

        # 再次尝试添加顶层权限
        try {
            icacls "$Folder" /C /Q /grant:r "$($TargetGroups[0]):$PermissionMask"
            $grantSuccess = $true
            Write-ToMyLog "Successfully added inherited permission after ownership change: $Folder"
        }
        catch {
            Write-ToMyLog "Failed to add permission even after ownership change: $Folder (Error: $_.Exception.Message)"
            continue
        }
    }

    # 如果权限添加成功,修复所有子对象的权限继承(清理中断继承的显式权限)
    if ($grantSuccess) {
        try {
            # /reset 重置子对象权限为继承自父项;/T 递归处理所有子对象
            icacls "$Folder" /C /Q /reset /T
            Write-ToMyLog "Successfully reset child permissions to inherit from top-level: $Folder"
        }
        catch {
            Write-ToMyLog "Warning: Failed to reset child permissions for: $Folder (Error: $_.Exception.Message). Some child objects may have explicit permissions remaining."
        }
    }
}

关键参数说明

  • /grant:r:替换目标组已有的权限条目,避免重复添加相同权限
  • 移除/T参数:仅在顶层文件夹添加权限,依靠(OI)(CI)属性实现自动向下继承
  • takeown /R /A /D Y:递归获取当前文件夹树的所有权,将所有权赋予域管理员组(而非当前用户),自动确认所有系统提示
  • icacls /reset /T:重置子对象的权限为继承自父文件夹,清理之前中断继承的显式权限,确保顶层新权限能正常传递

注意事项

  • 脚本需以域管理员权限运行
  • 如果需要保留特定子对象的显式权限,需移除/reset /T部分,或添加路径过滤逻辑跳过指定对象
  • 处理超大规模文件系统时,建议分批次处理文件夹,避免长时间运行导致中断

内容的提问来源于stack exchange,提问作者Tanaka Saito

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 23:35:56