You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell查看文件夹权限的Inherited from(继承来源)

获取文件夹权限的继承来源(PowerShell实现)

Get-Acl命令返回的权限对象默认不会直接显示继承来源路径,但可以通过向上遍历父文件夹、检查直接分配权限的方式找到继承来源。

以下是一个自定义PowerShell函数,可用于定位指定主体账户的权限继承来源文件夹:

function Get-PermissionInheritanceSource {
    param(
        [Parameter(Mandatory=$true)]
        [string]$FolderPath,
        [Parameter(Mandatory=$true)]
        [string]$Principal
    )

    $currentPath = Resolve-Path $FolderPath -ErrorAction Stop
    $foundSource = $false

    while ($currentPath -and -not $foundSource) {
        $acl = Get-Acl -Path $currentPath
        # 筛选当前主体的非继承权限(直接分配的权限)
        $directAccessRule = $acl.Access | Where-Object {
            $_.IdentityReference.Value -eq $Principal -and -not $_.IsInherited
        }

        if ($directAccessRule) {
            Write-Output "指定主体的权限继承来源:$currentPath"
            $foundSource = $true
        } else {
            $parentPath = Split-Path -Path $currentPath -Parent
            # 到达根目录时终止循环
            if ($parentPath -eq $currentPath) {
                Write-Output "未找到$Principal的直接分配权限,权限可能继承自根目录或未设置"
                $foundSource = $true
            }
            $currentPath = $parentPath
        }
    }
}

使用方法

执行以下命令,替换目标文件夹路径和主体账户名:

Get-PermissionInheritanceSource -FolderPath "C:\Example\TargetFolder" -Principal "CONTOSO\JohnDoe"

说明

  • 函数会从目标文件夹开始,逐层向上遍历父目录
  • 当找到包含指定主体**直接分配权限(非继承)**的文件夹时,该文件夹即为权限的继承来源
  • 若遍历到根目录仍未找到直接分配的权限,会提示权限可能继承自根目录或无直接分配项

内容的提问来源于stack exchange,提问作者JoshLamberth

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 12:22:37