You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell的ACL配置限制本地管理员修改指定快捷方式?

Fixing ACL Permissions for Protected Shortcuts

The issue with your original script is that using a Deny Modify rule blocks more than just modification rights—since Modify is a composite permission that includes ReadAndExecute, the Deny rule overrides any existing Allow permissions for execution, making the shortcut unrunnable. Instead of using Deny (which can cause unintended permission conflicts), we should adjust the Allow permissions for local administrators to restrict them to only ReadAndExecute access.

Here's the corrected PowerShell script to achieve your goal:

# Define the path to your shortcut
$shortcutPath = "C:\Users\Public\Desktop\Browser - PROD.lnk"

# Get the current ACL of the shortcut
$acl = Get-Acl -Path $shortcutPath

# Target the built-in Administrators group
$identity = "BUILTIN\Administrators"

# Step 1: Remove existing Allow rules that grant Modify access to Administrators
$existingModifyRules = $acl.Access | Where-Object {
    $_.IdentityReference -eq $identity -and
    $_.AccessControlType -eq "Allow" -and
    $_.FileSystemRights -match "Modify"
}

foreach ($rule in $existingModifyRules) {
    $acl.RemoveAccessRule($rule)
}

# Step 2: Add a new Allow rule granting only ReadAndExecute access
$fileSystemRights = [System.Security.AccessControl.FileSystemRights]::ReadAndExecute
$inheritanceFlags = [System.Security.AccessControl.InheritanceFlags]::None
$propagationFlags = [System.Security.AccessControl.PropagationFlags]::None
$accessControlType = [System.Security.AccessControl.AccessControlType]::Allow

$newRule = New-Object -TypeName System.Security.AccessControl.FileSystemAccessRule(
    $identity,
    $fileSystemRights,
    $inheritanceFlags,
    $propagationFlags,
    $accessControlType
)

$acl.AddAccessRule($newRule)

# Step 3: Apply the updated ACL to the shortcut
Set-Acl -Path $shortcutPath -AclObject $acl

Key Explanations:

  • Avoid Deny Rules: Deny permissions take precedence over all Allow permissions, so even if administrators had explicit ReadAndExecute access, a Deny Modify rule would block execution. By adjusting Allow permissions directly, we avoid this conflict.
  • Restrict to ReadAndExecute: This permission allows administrators to run the shortcut (and read its properties) but prevents them from modifying the target path, arguments, or deleting the shortcut.
  • Preserve Other Permissions: The script only modifies rules for the BUILTIN\Administrators group, leaving permissions for SYSTEM, Users, or other accounts intact.

After running this script, local administrators will be able to launch the shortcut normally but won't have the ability to edit or delete it.

内容的提问来源于stack exchange,提问作者degett

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 07:37:27