You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell变量配置ACL权限异常,显示SID而非用户名求助

批量创建AD用户后ACL权限显示SID而非用户名

问题详情

批量从CSV文件读取用户信息,自动创建AD用户、主目录并配置ACL权限,但配置后主目录的权限列表里不显示用户名(比如Joe Blogs),而是显示类似“SID 03752-572023-23289047”的内容。手动把ACL命令里的$user.username换成实际用户名,权限显示就正常,而且echo $user.username输出的用户名完全正确。

原脚本如下:

Import-Module ActiveDirectory

#Store the data from Users.csv in the $Users variable
$Users = Import-csv C:\UserList.csv

#Loop through each row containing user details in the CSV file 
foreach ($User in $Users)
{
    #Read user data from each field in each row and assign the data to a variable as below
        
    $Username = $User.username
    $Password = $User.password
    $Firstname = $User.firstname
    $Lastname = $User.lastname
    $OU = $User.ou 
    $Password = $User.Password
    $Path = "\\mydomainhere\Home$\Staff\CAAccounts\$($user.username)"

        
        #Account will be created in the OU provided by the $OU variable read from the CSV file
        New-ADUser `
    -SamAccountName $Username `
    -UserPrincipalName "$Username@fromecollege.org" `
    -Name "(CA) $Firstname $Lastname" `
    -GivenName $Firstname `
    -Surname $Lastname `
    -Enabled $True `
    -DisplayName "(CA) $Firstname $Lastname" `
    -Path $OU `
    -City $city `
    -Company $company `
    -State $state `
    -StreetAddress $streetaddress `
    -OfficePhone $telephone `
    -EmailAddress $email `
    -Title $jobtitle `
    -Department $department `
    -HomeDrive "N" `
    -HomeDirectory $Path `
    -ProfilePath "C:\profiles\basic.man" `
    -AccountPassword (convertto-securestring $Password -AsPlainText -Force) -ChangePasswordAtLogon $True

    mkdir $Path
    
    $acl = Get-Acl $Path
  
    $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($user.username,"ExecuteFile", "ContainerInherit,ObjectInherit", "None", "Allow")  
    $acl.addAccessRule($AccessRule)  
    $acl | Set-Acl $Path  
  
    $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($user.username,"ReadData", "ContainerInherit,ObjectInherit", "None", "Allow")  
    $acl.addAccessRule($AccessRule)  
    $acl | Set-Acl $Path   
  
    $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($user.username,"ReadPermissions", "ContainerInherit,ObjectInherit", "None", "Allow")  
    $acl.addAccessRule($AccessRule)  
    $acl | Set-Acl $Path   
  
    $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($user.username,"ReadAttributes", "ContainerInherit,ObjectInherit", "None", "Allow")  
    $acl.addAccessRule($AccessRule)  
    $acl | Set-Acl $Path    
  
    $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($user.username,"ReadExtendedAttributes", "ContainerInherit,ObjectInherit", "None", "Allow")  
    $acl.addAccessRule($AccessRule)  
    $acl | Set-Acl $Path   
    
    $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($user.username,"FullControl", "ContainerInherit,ObjectInherit", "None", "Allow")  
    $acl.addAccessRule($AccessRule)  
    $acl | Set-Acl $Path   

}

原因分析

  1. AD同步延迟:刚创建完AD用户,域控制器还没完成同步复制,本地系统没法把$user.username解析成对应的AD用户对象,只能用SID来记录权限。虽然变量输出的用户名是对的,但系统设置ACL时找不到完整的用户AD信息。
  2. 权限规则冗余:原脚本里先单独设置ExecuteFile、ReadData等基础权限,最后又设置FullControl,完全没必要,FullControl已经包含了所有基础权限,冗余设置反而可能引发权限叠加问题。

解决方案

1. 添加AD用户同步等待

创建用户后,等域控制器同步完成,再配置ACL:

# 创建用户后,循环验证用户是否已存在于AD中
do {
    Start-Sleep -Seconds 2
    $adUser = Get-ADUser -Filter "SamAccountName -eq '$Username'" -ErrorAction SilentlyContinue
} while (-not $adUser)

2. 使用AD用户SID创建ACL规则

直接用刚创建的AD用户的SID来生成权限规则,跳过用户名解析步骤:

# 获取刚创建的AD用户对象
$adUser = Get-ADUser -Identity $Username
# 用SID创建FullControl权限规则
$AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($adUser.SID,"FullControl", "ContainerInherit,ObjectInherit", "None", "Allow")
$acl.AddAccessRule($AccessRule)
$acl | Set-Acl $Path

3. 简化冗余权限设置

删掉单独的基础权限设置,只保留FullControl即可,减少代码冗余。

修改后的完整脚本

Import-Module ActiveDirectory

# 读取CSV中的用户数据
$Users = Import-csv C:\UserList.csv

foreach ($User in $Users) {
    $Username = $User.username
    $Password = $User.password
    $Firstname = $User.firstname
    $Lastname = $User.lastname
    $OU = $User.ou 
    $Path = "\\mydomainhere\Home$\Staff\CAAccounts\$Username"

    # 创建AD用户
    New-ADUser `
        -SamAccountName $Username `
        -UserPrincipalName "$Username@fromecollege.org" `
        -Name "(CA) $Firstname $Lastname" `
        -GivenName $Firstname `
        -Surname $Lastname `
        -Enabled $True `
        -DisplayName "(CA) $Firstname $Lastname" `
        -Path $OU `
        -City $User.city `
        -Company $User.company `
        -State $User.state `
        -StreetAddress $User.streetaddress `
        -OfficePhone $User.telephone `
        -EmailAddress $User.email `
        -Title $User.jobtitle `
        -Department $User.department `
        -HomeDrive "N" `
        -HomeDirectory $Path `
        -ProfilePath "C:\profiles\basic.man" `
        -AccountPassword (ConvertTo-SecureString $Password -AsPlainText -Force) `
        -ChangePasswordAtLogon $True

    # 检查并创建主目录
    if (-not (Test-Path $Path)) {
        New-Item -ItemType Directory -Path $Path | Out-Null
    }

    # 等待AD用户同步完成
    do {
        Start-Sleep -Seconds 2
        $adUser = Get-ADUser -Filter "SamAccountName -eq '$Username'" -ErrorAction SilentlyContinue
    } while (-not $adUser)

    # 配置主目录ACL权限
    $acl = Get-Acl $Path
    $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule(
        $adUser.SID,
        "FullControl",
        "ContainerInherit,ObjectInherit",
        "None",
        "Allow"
    )
    $acl.AddAccessRule($AccessRule)
    $acl | Set-Acl $Path
}

内容的提问来源于stack exchange,提问作者OhMyEnglishTeaBags

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 11:20:37