You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell Set-Acl遇错误代码59,大体积数据集权限配置失败求助

问题

现有PowerShell脚本用于配置文件和文件夹NTFS权限,小数据集下运行正常,但处理10+TB的大型数据集时触发报错;同时使用Windows资源管理器执行相同操作,会提示“发生意外网络错误”。

原脚本内容

#This PS Script will add NTFS Permissions
#Create the ACE
#This command will display the NTFS Perms prior to making the NTFS Perm changes for comparison 
(Get-Acl -Path "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS").Access | Format-Table -Autosize
#$identity = input the AD account to add user, use the below format
$identity = 'domain\username'
#$rights = This is the equivalent NTFS Permissions that are displayed on the Security tab 
$rights = 'Modify' #Other options: [enum]::GetValues('System.Security.AccessControl.FileSystemRights')
$inheritance = 'ContainerInherit, ObjectInherit' #Other options: [enum]::GetValues('System.Security.AccessControl.Inheritance')
$propagation = 'None' #Other options: [enum]::GetValues('System.Security.AccessControl.PropagationFlags')
$type = 'Allow' #Other options: [enum]::GetValues('System.Security.AccessControl.AccessControlType')
$ACE = New-Object System.Security.AccessControl.FileSystemAccessRule($identity,$rights,$inheritance,$propagation, $type)
#-Path is the path that will be modified with the new NTFS permissions, all folders, and files below this will obtain the NTFS perms 
$Acl = Get-Acl -Path "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS"
$Acl.AddAccessRule($ACE)
Set-Acl -Path "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS" -AclObject $Acl
#This command will display the changes after the NTFS Perms have been set so they can be compared to the per change Perms 
(Get-Acl -Path "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS").Access | Format-Table -Autosize

报错信息

Set-Acl : Method failed with unexpected error code 59.
At C:\Scripts\Adding_NTFS_Perms.ps1:18 char:1
+ Set-Acl -Path "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\ ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : InvalidOperation: (\xx\xx\xxxx1...\xxxxx xxxxx:String) [Set-Acl], InvalidOperationException
    + FullyQualifiedErrorId : System.InvalidOperationException,Microsoft.PowerShell.Commands.SetAclCommand

解决方案

1. 改用icacls替代Set-Acl

大数据集下Set-Acl易因资源占用或网络超时触发错误,icacls是Windows原生命令行工具,处理大规模权限变更更稳定:

# 替换原Set-Acl相关代码,直接用icacls添加权限
$targetPath = "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS"
icacls $targetPath /grant "domain\username:(OI)(CI)M" /T
  • /grant:添加允许权限
  • (OI)(CI):对应ObjectInherit、ContainerInherit继承规则
  • M:对应Modify权限
  • /T:递归处理所有子文件和文件夹

2. 分批次递归处理子目录

若必须用PowerShell实现,可拆分任务逐个处理子目录,避免一次性加载所有ACL数据:

$targetPath = "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS"
$identity = 'domain\username'
$rights = 'Modify'
$inheritance = 'ContainerInherit, ObjectInherit'
$propagation = 'None'
$type = 'Allow'
$ACE = New-Object System.Security.AccessControl.FileSystemAccessRule($identity,$rights,$inheritance,$propagation, $type)

# 先处理根目录
$acl = Get-Acl $targetPath
$acl.AddAccessRule($ACE)
Set-Acl $targetPath -AclObject $acl

# 递归获取子目录,逐个处理并增加重试逻辑
Get-ChildItem $targetPath -Directory -Recurse | ForEach-Object {
    try {
        $acl = Get-Acl $_.FullName
        $acl.AddAccessRule($ACE)
        Set-Acl $_.FullName -AclObject $acl
        Write-Host "已处理: $($_.FullName)"
    }
    catch {
        Write-Warning "处理失败: $($_.FullName) - $($_.Exception.Message)"
        Start-Sleep -Seconds 2
        # 重试一次
        try {
            $acl = Get-Acl $_.FullName
            $acl.AddAccessRule($ACE)
            Set-Acl $_.FullName -AclObject $acl
            Write-Host "重试成功: $($_.FullName)"
        }
        catch {
            Write-Error "重试失败: $($_.FullName) - $($_.Exception.Message)"
        }
    }
}

3. 调整继承策略减少递归压力

如果不需要立即将权限同步到所有文件,可先修改根目录权限,再禁用继承并保留现有权限,后续按需同步:

$targetPath = "$dir\xx\xx\xxxx1047\xxxxx\x\x\x\xxxxx\xxxxx\TEST-NTFS-PERMS"
# 修改根目录权限
$acl = Get-Acl $targetPath
$acl.AddAccessRule($ACE)
# 禁用继承并保留现有权限
$acl.SetAccessRuleProtection($true, $true)
Set-Acl $targetPath -AclObject $acl
# 后续可按需用icacls同步指定子目录

4. 排查底层环境问题

错误代码59和“意外网络错误”多与存储/网络稳定性相关:

  • 避开存储阵列负载高峰时段执行操作
  • 若为共享目录,尝试在存储服务器本地执行脚本
  • 关闭无关后台进程,释放系统资源

内容的提问来源于stack exchange,提问作者wilco1990

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 21:40:52