You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell自提权脚本循环问题及UAC默认账户设置需求

解决方案

1. 解决非管理员凭据输入后的无限循环问题

原脚本在用户输入非管理员凭据后,新启动的进程仍会触发自提权逻辑,导致无限循环。通过添加SkipElevationCheck标记参数,让二次启动的脚本跳过自提权检查,直接验证权限并退出:

# 检查是否已跳过提升检查
if (-not $MyInvocation.BoundParameters.ContainsKey('SkipElevationCheck')) {
    $currentPrincipal = New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())
    if (-not $currentPrincipal.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) {
        # 构造带标记的启动参数
        $arguments = @(
            '-NoProfile',
            '-ExecutionPolicy Bypass',
            '-Command',
            "cd '$pwd'; & '$PSCommandPath' -SkipElevationCheck"
        )
        $process = Start-Process PowerShell -Verb RunAs -ArgumentList $arguments -PassThru
        $process.WaitForExit()
        exit $process.ExitCode
    }
} else {
    # 验证权限,非管理员直接报错退出
    $currentPrincipal = New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())
    if (-not $currentPrincipal.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) {
        Write-Error "未获得管理员权限,脚本无法继续执行。"
        exit 1
    }
}

# 主代码区域
# 此处添加删除USB管控注册表项的逻辑,示例:
# Remove-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\USBSTOR" -Name "Start" -ErrorAction SilentlyContinue

2. 让凭据框默认显示指定账户

若要默认显示ROOT\install账户,可替换-Verb RunAs为-Credential参数,弹出预填用户名的凭据输入框:

# 检查是否已跳过提升检查
if (-not $MyInvocation.BoundParameters.ContainsKey('SkipElevationCheck')) {
    $currentPrincipal = New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())
    if (-not $currentPrincipal.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) {
        # 预填指定账户,弹出凭据输入框
        $credential = Get-Credential -UserName "ROOT\install" -Message "请输入管理员账户密码"
        if (-not $credential) {
            Write-Error "未提供凭据,脚本终止。"
            exit 1
        }
        # 构造带标记的启动参数
        $arguments = @(
            '-NoProfile',
            '-ExecutionPolicy Bypass',
            '-Command',
            "cd '$pwd'; & '$PSCommandPath' -SkipElevationCheck"
        )
        # 使用指定凭据启动进程
        $process = Start-Process PowerShell -Credential $credential -ArgumentList $arguments -PassThru
        $process.WaitForExit()
        exit $process.ExitCode
    }
} else {
    # 验证权限,非管理员直接报错退出
    $currentPrincipal = New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())
    if (-not $currentPrincipal.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) {
        Write-Error "未获得管理员权限,脚本无法继续执行。"
        exit 1
    }
}

# 主代码区域
# 此处添加删除USB管控注册表项的逻辑

3. 执行策略兼容性说明

当前MachinePolicy和LocalMachine为RemoteSigned,脚本存于本地,-ExecutionPolicy Bypass参数可正常绕过执行策略限制,无需对脚本签名,符合你的环境需求。

内容的提问来源于stack exchange,提问作者William Lombard

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 07:35:35