PowerShell变量配置ACL权限异常,显示SID而非用户名求助
批量创建AD用户后ACL权限显示SID而非用户名
问题详情
批量从CSV文件读取用户信息,自动创建AD用户、主目录并配置ACL权限,但配置后主目录的权限列表里不显示用户名(比如Joe Blogs),而是显示类似“SID 03752-572023-23289047”的内容。手动把ACL命令里的$user.username换成实际用户名,权限显示就正常,而且echo $user.username输出的用户名完全正确。
原脚本如下:
Import-Module ActiveDirectory #Store the data from Users.csv in the $Users variable $Users = Import-csv C:\UserList.csv #Loop through each row containing user details in the CSV file foreach ($User in $Users) { #Read user data from each field in each row and assign the data to a variable as below $Username = $User.username $Password = $User.password $Firstname = $User.firstname $Lastname = $User.lastname $OU = $User.ou $Password = $User.Password $Path = "\\mydomainhere\Home$\Staff\CAAccounts\$($user.username)" #Account will be created in the OU provided by the $OU variable read from the CSV file New-ADUser ` -SamAccountName $Username ` -UserPrincipalName "$Username@fromecollege.org" ` -Name "(CA) $Firstname $Lastname" ` -GivenName $Firstname ` -Surname $Lastname ` -Enabled $True ` -DisplayName "(CA) $Firstname $Lastname" ` -Path $OU ` -City $city ` -Company $company ` -State $state ` -StreetAddress $streetaddress ` -OfficePhone $telephone ` -EmailAddress $email ` -Title $jobtitle ` -Department $department ` -HomeDrive "N" ` -HomeDirectory $Path ` -ProfilePath "C:\profiles\basic.man" ` -AccountPassword (convertto-securestring $Password -AsPlainText -Force) -ChangePasswordAtLogon $True mkdir $Path $acl = Get-Acl $Path $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($user.username,"ExecuteFile", "ContainerInherit,ObjectInherit", "None", "Allow") $acl.addAccessRule($AccessRule) $acl | Set-Acl $Path $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($user.username,"ReadData", "ContainerInherit,ObjectInherit", "None", "Allow") $acl.addAccessRule($AccessRule) $acl | Set-Acl $Path $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($user.username,"ReadPermissions", "ContainerInherit,ObjectInherit", "None", "Allow") $acl.addAccessRule($AccessRule) $acl | Set-Acl $Path $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($user.username,"ReadAttributes", "ContainerInherit,ObjectInherit", "None", "Allow") $acl.addAccessRule($AccessRule) $acl | Set-Acl $Path $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($user.username,"ReadExtendedAttributes", "ContainerInherit,ObjectInherit", "None", "Allow") $acl.addAccessRule($AccessRule) $acl | Set-Acl $Path $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($user.username,"FullControl", "ContainerInherit,ObjectInherit", "None", "Allow") $acl.addAccessRule($AccessRule) $acl | Set-Acl $Path }
原因分析
- AD同步延迟:刚创建完AD用户,域控制器还没完成同步复制,本地系统没法把
$user.username解析成对应的AD用户对象,只能用SID来记录权限。虽然变量输出的用户名是对的,但系统设置ACL时找不到完整的用户AD信息。 - 权限规则冗余:原脚本里先单独设置ExecuteFile、ReadData等基础权限,最后又设置FullControl,完全没必要,FullControl已经包含了所有基础权限,冗余设置反而可能引发权限叠加问题。
解决方案
1. 添加AD用户同步等待
创建用户后,等域控制器同步完成,再配置ACL:
# 创建用户后,循环验证用户是否已存在于AD中 do { Start-Sleep -Seconds 2 $adUser = Get-ADUser -Filter "SamAccountName -eq '$Username'" -ErrorAction SilentlyContinue } while (-not $adUser)
2. 使用AD用户SID创建ACL规则
直接用刚创建的AD用户的SID来生成权限规则,跳过用户名解析步骤:
# 获取刚创建的AD用户对象 $adUser = Get-ADUser -Identity $Username # 用SID创建FullControl权限规则 $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($adUser.SID,"FullControl", "ContainerInherit,ObjectInherit", "None", "Allow") $acl.AddAccessRule($AccessRule) $acl | Set-Acl $Path
3. 简化冗余权限设置
删掉单独的基础权限设置,只保留FullControl即可,减少代码冗余。
修改后的完整脚本
Import-Module ActiveDirectory # 读取CSV中的用户数据 $Users = Import-csv C:\UserList.csv foreach ($User in $Users) { $Username = $User.username $Password = $User.password $Firstname = $User.firstname $Lastname = $User.lastname $OU = $User.ou $Path = "\\mydomainhere\Home$\Staff\CAAccounts\$Username" # 创建AD用户 New-ADUser ` -SamAccountName $Username ` -UserPrincipalName "$Username@fromecollege.org" ` -Name "(CA) $Firstname $Lastname" ` -GivenName $Firstname ` -Surname $Lastname ` -Enabled $True ` -DisplayName "(CA) $Firstname $Lastname" ` -Path $OU ` -City $User.city ` -Company $User.company ` -State $User.state ` -StreetAddress $User.streetaddress ` -OfficePhone $User.telephone ` -EmailAddress $User.email ` -Title $User.jobtitle ` -Department $User.department ` -HomeDrive "N" ` -HomeDirectory $Path ` -ProfilePath "C:\profiles\basic.man" ` -AccountPassword (ConvertTo-SecureString $Password -AsPlainText -Force) ` -ChangePasswordAtLogon $True # 检查并创建主目录 if (-not (Test-Path $Path)) { New-Item -ItemType Directory -Path $Path | Out-Null } # 等待AD用户同步完成 do { Start-Sleep -Seconds 2 $adUser = Get-ADUser -Filter "SamAccountName -eq '$Username'" -ErrorAction SilentlyContinue } while (-not $adUser) # 配置主目录ACL权限 $acl = Get-Acl $Path $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule( $adUser.SID, "FullControl", "ContainerInherit,ObjectInherit", "None", "Allow" ) $acl.AddAccessRule($AccessRule) $acl | Set-Acl $Path }
内容的提问来源于stack exchange,提问作者OhMyEnglishTeaBags
相关产品推荐
相关产品推荐

