PowerShell Set-Acl遇错误代码59,大体积数据集权限配置失败求助
问题
现有PowerShell脚本用于配置文件和文件夹NTFS权限,小数据集下运行正常,但处理10+TB的大型数据集时触发报错;同时使用Windows资源管理器执行相同操作,会提示“发生意外网络错误”。
原脚本内容
#This PS Script will add NTFS Permissions #Create the ACE #This command will display the NTFS Perms prior to making the NTFS Perm changes for comparison (Get-Acl -Path "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS").Access | Format-Table -Autosize #$identity = input the AD account to add user, use the below format $identity = 'domain\username' #$rights = This is the equivalent NTFS Permissions that are displayed on the Security tab $rights = 'Modify' #Other options: [enum]::GetValues('System.Security.AccessControl.FileSystemRights') $inheritance = 'ContainerInherit, ObjectInherit' #Other options: [enum]::GetValues('System.Security.AccessControl.Inheritance') $propagation = 'None' #Other options: [enum]::GetValues('System.Security.AccessControl.PropagationFlags') $type = 'Allow' #Other options: [enum]::GetValues('System.Security.AccessControl.AccessControlType') $ACE = New-Object System.Security.AccessControl.FileSystemAccessRule($identity,$rights,$inheritance,$propagation, $type) #-Path is the path that will be modified with the new NTFS permissions, all folders, and files below this will obtain the NTFS perms $Acl = Get-Acl -Path "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS" $Acl.AddAccessRule($ACE) Set-Acl -Path "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS" -AclObject $Acl #This command will display the changes after the NTFS Perms have been set so they can be compared to the per change Perms (Get-Acl -Path "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS").Access | Format-Table -Autosize
报错信息
Set-Acl : Method failed with unexpected error code 59. At C:\Scripts\Adding_NTFS_Perms.ps1:18 char:1 + Set-Acl -Path "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\ ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : InvalidOperation: (\xx\xx\xxxx1...\xxxxx xxxxx:String) [Set-Acl], InvalidOperationException + FullyQualifiedErrorId : System.InvalidOperationException,Microsoft.PowerShell.Commands.SetAclCommand
解决方案
1. 改用icacls替代Set-Acl
大数据集下Set-Acl易因资源占用或网络超时触发错误,icacls是Windows原生命令行工具,处理大规模权限变更更稳定:
# 替换原Set-Acl相关代码,直接用icacls添加权限 $targetPath = "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS" icacls $targetPath /grant "domain\username:(OI)(CI)M" /T
/grant:添加允许权限(OI)(CI):对应ObjectInherit、ContainerInherit继承规则M:对应Modify权限/T:递归处理所有子文件和文件夹
2. 分批次递归处理子目录
若必须用PowerShell实现,可拆分任务逐个处理子目录,避免一次性加载所有ACL数据:
$targetPath = "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS" $identity = 'domain\username' $rights = 'Modify' $inheritance = 'ContainerInherit, ObjectInherit' $propagation = 'None' $type = 'Allow' $ACE = New-Object System.Security.AccessControl.FileSystemAccessRule($identity,$rights,$inheritance,$propagation, $type) # 先处理根目录 $acl = Get-Acl $targetPath $acl.AddAccessRule($ACE) Set-Acl $targetPath -AclObject $acl # 递归获取子目录,逐个处理并增加重试逻辑 Get-ChildItem $targetPath -Directory -Recurse | ForEach-Object { try { $acl = Get-Acl $_.FullName $acl.AddAccessRule($ACE) Set-Acl $_.FullName -AclObject $acl Write-Host "已处理: $($_.FullName)" } catch { Write-Warning "处理失败: $($_.FullName) - $($_.Exception.Message)" Start-Sleep -Seconds 2 # 重试一次 try { $acl = Get-Acl $_.FullName $acl.AddAccessRule($ACE) Set-Acl $_.FullName -AclObject $acl Write-Host "重试成功: $($_.FullName)" } catch { Write-Error "重试失败: $($_.FullName) - $($_.Exception.Message)" } } }
3. 调整继承策略减少递归压力
如果不需要立即将权限同步到所有文件,可先修改根目录权限,再禁用继承并保留现有权限,后续按需同步:
$targetPath = "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS" # 修改根目录权限 $acl = Get-Acl $targetPath $acl.AddAccessRule($ACE) # 禁用继承并保留现有权限 $acl.SetAccessRuleProtection($true, $true) Set-Acl $targetPath -AclObject $acl # 后续可按需用icacls同步指定子目录
4. 排查底层环境问题
错误代码59和“意外网络错误”多与存储/网络稳定性相关:
- 避开存储阵列负载高峰时段执行操作
- 若为共享目录,尝试在存储服务器本地执行脚本
- 关闭无关后台进程,释放系统资源
内容的提问来源于stack exchange,提问作者wilco1990
相关产品推荐
相关产品推荐

